Impact
The Linux kernel drm/amd/display subsystem contains a division by zero bug in get_estimated_bw(). The function divides the bandwidth allocation granularity by link->dpia_bw_alloc_config.bw_granularity, which remains zero unless a capability change has been processed. If a USB4/DPIA tunneling device reports an estimated‑bandwidth change before reporting a capability change, an IRQ handler will trigger this division by zero, leading to a kernel fault and system crash. This is a pure runtime error that can be triggered when the device is connected.
Affected Systems
All Linux kernel versions that include the drm/amd/display driver prior to the fix, regardless of distribution, are affected. The issue appears in the AMD display DRM infrastructure used by many modern systems. No specific kernel version range is listed, but any kernel with the unpatched AMD display component is vulnerable.
Risk and Exploitability
The EPSS score indicates a probability of exploitation in the <1% range, and the vulnerability is not listed in CISA’s KEV catalog. The path to exploitation is local: a faulty USB4/DPIA tunneling device must be connected to the target system. Because the flaw triggers only during certain interrupt handling, the attack surface is limited. The impact is a denial of service via kernel panic, with no remote code execution or persistence possible.
OpenCVE Enrichment
Debian DLA
Debian DSA