Impact
The vulnerability involves the AMDGPU driver for GFX6 GPUs in the Linux kernel, where compute queues previously did not use the PFP interface for register writes and pipeline synchronization. The lack of PFP handling caused the driver to wait for an incorrect fence, potentially allowing compute queue submissions to proceed prematurely. This mis‑synchronization could lead to inconsistent GPU state, unintended data exposure, or GPU stalls, effectively creating a denial of service path for workloads that rely on compute queues.
Affected Systems
Affected systems are Linux kernel installations that incorporate the AMDGPU driver for GFX6 GPUs, such as AMD Vega or older GPUs with GFX6 silicon. All kernel versions prior to the patch that exposed the compute queue PFP handling oversight are vulnerable, regardless of distribution or patch level.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of current exploitation. Because the issue resides in kernel driver code, an attacker would need to inject GPU commands that target compute queues on a GFX6 GPU – a scenario typically confined to systems with local or privileged access to the GPU. The vulnerability was not listed in the CISA KEV catalog, meaning no publicly known exploits are yet causing widespread attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA