Impact
This vulnerability arises from missing validation of the size of a per‑plane degamma Look‑Up Table in the AMD display driver. The driver accepts a user‑supplied size and passes it through a linearity check and a conversion routine that always iterates a fixed number of entries, regardless of the actual size. A malformed blob—such as a single entry—can therefore trigger a divide‑by‑zero during the linearity test or an out‑of‑bounds read while converting the table. The result is kernel memory corruption that can lead to a crash or, in the worst case, arbitrary code execution. The weakness is an instance of improper input validation (CWE‑20).
Affected Systems
The flaw exists in any Linux kernel that builds the AMD display driver with the AMD_PRIVATE_COLOR option enabled. The AMD_PLANE_DEGAMMA_LUT property is thus only exposed on those builds. The issue affects all architectures that compile this driver, but no specific kernel versions are listed in the advisory, so any recent kernel containing the vulnerable code path is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1 % shows a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: an attacker with the ability to set the AMD_PLANE_DEGAMMA_LUT property—typically a privileged process or a user with elevated rights—can supply a malformed table and trigger the fault. The lack of bounds checking makes the crash deterministic once the malicious input is delivered, but leveraging the out‑of‑bounds read to gain code execution would require further stack or memory corruption techniques not detailed in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA