Impact
The amdgpu driver in the Linux kernel contains a bug where the VRAM manager initialization routine performs region registration before fully setting up internal data structures. If region registration fails, the cleanup path is entered with uninitialized list heads and buddy allocator structures, causing null pointer dereferences and a kernel panic. An attacker who can cause the driver to be initialized under those conditions would be able to crash the system, resulting in a denial‑of‑service and potentially allowing further exploitation through the kernel panic.
Affected Systems
Linux kernels that include the AMDGPU driver before the commit that corrected the init ordering. The vulnerability is present in all kernel releases lacking the patch, which affect machines that load the amdgpu driver during boot or when a GPU device is accessed.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a low probability of automated exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the defect causes a kernel panic, a high‑severity denial of service. Because the flaw manifests during driver load, it can be triggered by early boot activities or GPU usage, making it potentially reachable by local users with sufficient privileges or specialized hardware access. The overall risk is moderate to high for systems that have not yet applied the patch.
OpenCVE Enrichment