Impact
In the Linux kernel, the amdkfd DRM driver incorrectly releases and unmaps system pages when migration from an AMD device’s GPU memory to system RAM fails. The driver uses the DMA address associated with the device instead of the physical frame number of the system page, causing the kernel to free or map incorrect memory. This error path can corrupt kernel memory that remains in use, leading to kernel crashes, data corruption, or the potential for arbitrary code execution. The flaw is a classic use‑after‑free or improper memory deallocation issue.
Affected Systems
All Linux kernel variants that include the AMD Kernel Framebuffer (amdkfd) DRM component are affected. Without a specific version list from the vendor, the issue potentially exists in any kernel release before the patch sequence referenced in the advisory. The vulnerability primarily impacts systems running AMD GPUs with the amdkfd driver enabled, regardless of distribution.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation would require local access, privilege escalation, or a vulnerability that triggers the defective migration path, and the attacker would need an IOMMU‑enabled environment to expose the bug. If successfully leveraged, the kernel memory corruption could lead to arbitrary code execution or system instability.
OpenCVE Enrichment