Impact
In the Linux kernel, a race condition in the AMDGPU display driver can cause a NULL pointer dereference. While a device manager (DM) teardown is underway, DM I2C adapters remain exposed to userspace. If an in‑flight i2c‑dev transfer is issued during this window, the kernel calls amdgpu_dm_i2c_xfer() after the underlying DM state has been dismantled, dereferencing a NULL pointer. The crash results in a kernel panic, effectively denying service to the affected system and potentially allowing a local attacker to trigger a privilege‑escalation exploit or disrupt critical services.
Affected Systems
The flaw affects the generic Linux kernel that includes the AMDGPU GPU drivers, particularly those where the DM I2C adapter lifespan was not properly scoped. No specific kernel version range is listed in the advisory, so any kernel build with the unpatched AMDGPU driver could be vulnerable until the patch that introduces a devres group around the DM I2C adapter is applied.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of widespread exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Because the issue requires a concurrent i2c‑dev request during device removal, the practical attack vector is likely local or involves privileged users with access to the device. If exploited, the outcome is a kernel crash, which can serve as a foothold for further attacks or, at minimum, cause an outage.
OpenCVE Enrichment