Impact
In the Linux kernel, the AMD display driver contains a flaw where the dc_lock is taken during a GPU reset and is not released if certain error paths are taken. When the lock remains held, subsequent attempts to acquire it block forever, halting GPU operations and any application that depends on graphics. This results in a kernel‑level deadlock that effectively renders the GPU unusable until a system reboot, causing a denial of service for graphical sessions. The vulnerability is identified as a resource leak involving an exclusive lock, grouped under CWE-772.
Affected Systems
All Linux kernel versions that include the AMD display driver but lack the patch are affected. Because the vulnerability is in the kernel’s DRM subsystem, every distribution shipping the stock kernel prior to the merge of the fix is vulnerable. The exact affected build series cannot be determined from the data, but any kernel lacking the commit that releases the dc_lock on error paths is impacted.
Risk and Exploitability
The vulnerability is a resource leak involving the dc_lock in the AMD display driver. When the kernel attempts a GPU reset and certain initialization functions fail, the lock is never released. This means any subsequent attempt to acquire the lock blocks indefinitely, effectively disabling all further GPU activity and causing a graphical system hang. The CVE description does not specify how to trigger the error path, and no attack vector is explicitly documented. It is reasonable to infer that the flaw would be exercised during normal kernel operation when a GPU reset occurs or if an error in the driver path is triggered, but this inference is not confirmed by the advisory. The CVSS score of 5.5 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment