Impact
The AMDGPU driver contains a loop that iterates only a fixed number of times (AMDGPU_MAX_MES_PIPES), which is insufficient for multi-XCC GPUs where the number of XCCs can be larger. When a job is queued for an XCC ID greater than or equal to 2, the driver indexes an array that, because of the loop limit, was never initialized. This results in a null pointer dereference inside the kernel, which will trigger a panic and reboot the system. The impact is a disruption of service and could be leveraged to crash systems that rely on high‑performance GPUs. The vulnerability is an example of CWE‑476, a null pointer dereference.
Affected Systems
All Linux kernel versions that include the buggy AMDGPU driver before the patch referenced in this advisory. Users of systems with multi‑XCC GPUs (i.e., GPUs supporting more than one XCC) are affected. Exact kernel release information is not provided, but any kernel containing the older loop implementation is vulnerable.
Risk and Exploitability
The EPSS score is below 1 percent, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Because the defect occurs within the kernel driver, it requires privileged kernel execution context or direct interaction with the GPU driver to trigger. An attacker would need to supply workloads targeting an XCC ID beyond the loop boundary. Due to the kernel panic it can cause a denial of service, but there is no evidence of code execution or data exfiltration from the information given.
OpenCVE Enrichment