Impact
The Linux kernel's AMDX DNA driver incorrectly handles a SYNC_BO ioctl request that specifies a zero-length buffer. The driver forwards the request to drm_clflush_virt_range, which calculates an interval ending at the start of the buffer. Because the interval is empty, the function performs an unconditional clflushopt on the address immediately before the buffer. In a zero-size case this address lands in the guard page below the vmalloc area, causing a page fault and a kernel panic. Any process that can open a render node can issue such an ioctl, which means an ordinary local user can trigger a full system crash.
Affected Systems
Affected systems include any Linux kernel running the AMD XDNA GPU driver, such as the Strix Point NPU (1022:17f0) or other AMD XDNA devices. The vulnerability is present in kernels before the fix commit, so all releases prior to the patch are affected.
Risk and Exploitability
The EPSS score is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the crash from any user that can access a render node; no network or privilege escalation is required. While the fault causes a complete kernel panic, the lack of a known remote or high-privilege exploit keeps the overall risk moderate, but the defect remains a serious denial‑of‑service vector for local users.
OpenCVE Enrichment