Impact
The flaw in the Linux kernel's amdgpu driver causes the system to force‑complete a UVD decode ring that has never been initialized when an SR‑IOV virtual function is resumed. Because the ring buffer state is bogus, the forced completion can corrupt kernel memory or trigger an assertion, potentially leading to a kernel crash or denial of service. The weakness stems from improper initialization and subsequent blind operation on uninitialized data.
Affected Systems
This issue affects the Linux kernel and, more specifically, the amdgpu device driver on systems that enable SR‑IOV to create virtual functions. The patch is included in kernel commits identified in the provided references, but no explicit kernel version range is supplied, so any kernel build prior to those commits is potentially vulnerable. The vulnerability is limited to the virtual function context; standard physical GPUs are unaffected.
Risk and Exploitability
The EPSS score is below 1 % and the CVE is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. Nevertheless, the flaw allows an attacker to crash the kernel if they can trigger a resume of an uninitialized UVD ring, which typically requires kernel or root access. The attack vector is therefore inferred as a local privilege escalation or kernel exploit rather than remote abuse, but because it directly causes a denial of service, it remains a noteworthy risk for environments that rely on SR‑IOV GPU sharing.
OpenCVE Enrichment