Impact
The vulnerability arises from an off‑by‑one error in the AMDGPU driver where the macro AMDGPU_DM_MAX_DISPLAY_INDEX is set to 31 but the code actually expects a maximum of 32 connectors. This mismatch can cause an array index to reference one element beyond its allocated bounds, potentially leading to memory corruption. An attacker that can trigger the affected parts of the DRM subsystem could force the driver to read or write beyond the intended range, which could result in crashes or unpredictable behaviour. The description does not confirm whether the corruption could be exploited for arbitrary code execution; however, the possibility of memory corruption signifies a risk of system instability or denial of service.
Affected Systems
All Linux kernel installations that include the AMDGPU DRM driver are potentially affected. Exact kernel versions are not specified; the issue is present in the source code prior to the fix mentioned in the reference commits. Users running distributions with the default kernel should verify whether their kernel includes the updated array size of 32 elements.
Risk and Exploitability
The CVSS score of 7.8 classifies this as High severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector would involve local user access that can invoke AMDGPU DRM operations, though remote exploitation via display protocols cannot be ruled out without further information. Given the high severity score, the potential impact, and the difficulty of proving exploitation, the overall risk is significant enough to warrant prompt patching.
OpenCVE Enrichment