Impact
An out‑of‑bounds indexing bug in the Linux AMDGPU DRM driver can cause undefined kernel behavior when a ring is not assigned to a partition. The isolation index used for such rings is a special value that refers to a non‑existent array slot, leading to a memory corruption trigger that UBSAN reports and which can result in a kernel panic or data corruption. This flaw could be used to gain elevated privileges or destabilize the system.
Affected Systems
All Linux kernels that include the amdgpu driver before the fix are vulnerable; the issue was addressed in the kernel mainline around the commit from which the patch is derived. The vulnerability applies to every distribution that ships an unpatched AMDGPU driver.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate‑to‑high severity, yet the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, and no public exploits have been reported. The most likely attack scenario requires access to the victim’s machine or a privileged context that can submit SDMA commands, meaning local or system‑level compromise is required.
OpenCVE Enrichment