Impact
The vulnerability is an integer overflow in the decoding of a VCN buffer count value supplied by the AMD GPU driver. When the supplied msg[2] equals 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2, causing the bounds check to incorrectly succeed. The driver then parses beyond the end of the buffer object, corrupting kernel memory. This corruption can lead to a denial of service. Based on the description, it is inferred that such memory corruption could potentially enable code execution at the kernel level.
Affected Systems
All Linux kernel releases that include the amdgpu VCN driver are vulnerable until the kernel update that fixes the integer‑overflow is applied. No specific affected versions are listed, so any kernel prior to the patch that incorporates the fix is considered at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this flaw. The EPSS score of less than 1% suggests a relatively low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Triggering the overflow requires a specially crafted message and an approximately 4 GiB mapping, implying that the attacker needs local or privileged access to the GPU driver. There is no indication of a remote attack vector, so the risk is high but likely limited to local or privileged threat actors.
OpenCVE Enrichment
Debian DLA
Debian DSA