Impact
The vulnerability is a null pointer dereference in the AMD GPU KFD driver that occurs when a process reads /sys/kernel/debug/kfd/mqds while an active queue exists. Because the code mistakenly accesses mqd_mgr->debugfs_show_mqd() after the guard that initializes mqd_mgr, the pointer can be NULL. A kernel panic is triggered at that point, resulting in a denial of service on the affected system.
Affected Systems
All Linux kernel releases that include the AMD KFD driver and have not incorporated commit 8bfe29d5 (which moves the for‑loop inside the initialization guard) are vulnerable. The vulnerable code is part of the amdgpu module; hence any distribution using an unpatched amdgpu version before that commit is at risk. Exact version numbers are not provided, so any kernel from the time of the commit back to the module's release should be considered.
Risk and Exploitability
The EPSS score is indicated as less than 1 %, suggesting a very low likelihood of exploitation. The attack requires a local user who has read access to the kfd debugfs entries, permissions that are normally restricted to root or users with specific privileges. The vulnerability is not listed in the CISA KEV catalog. Therefore, while the potential impact is high (kernel crash), the probability of attack remains low under normal circumstances.
OpenCVE Enrichment