Impact
The issue concerns the isp4if_alloc_fw_gpumem function in the Linux kernel, which allocates multiple GPU memory pools sequentially. If any allocation fails, the function returns an ENOMEM error without releasing previously allocated pools, leaving them in an allocated state. This leak can accumulate over time, exhausting kernel memory and potentially leading to degraded performance or system instability. The vulnerability is a memory leak (CWE‑401) and a broader resource management error (CWE‑399).
Affected Systems
Affected systems are any Linux kernel installations that use the AMD ISP4 media subsystem. No specific kernel version is supplied, so the flaw may exist in all releases containing this function until the patch in commits a1f8750668e552837df781783909f2f680958006 and fea97ee13c5332f67850733d6cefc1fe99460bde is applied.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog, suggesting no known active exploit. An attacker would need local access to the kernel or the ability to invoke the ISP4 firmware allocation routine, possibly through privileged media operations. Such a local approach would result in a gradual depletion of kernel memory over time, but would not allow immediate code execution. The overall risk is low to medium, primarily associated with resource exhaustion if the failure conditions are repeatedly triggered.
OpenCVE Enrichment