Impact
The vulnerability lies in the amdgpu_dm_plane_drm_plane_reset() function within the Linux kernel's AMDGPU display driver. When allocation of a new plane state fails, the function exits without updating the state pointer, leaving it dangling to freed memory. This use‑after‑free could subsequently be dereferenced, corrupting kernel memory and potentially enabling arbitrary code execution by a privileged attacker.
Affected Systems
All Linux kernel builds that contain the amdgpu_dm module before the fix are affected. The issue is specific to the AMDGPU driver and does not impact other graphics drivers. Inferred: the affected hardware is likely AMD GPUs, but this is not explicitly stated.
Risk and Exploitability
The CVSS score of 7 indicates a severe impact if exploited. The EPSS score of <1% and the lack of a CISA KEV listing suggest a low probability of active exploitation. The use‑after‑free in kernel space could enable arbitrary code execution; however, the specific attack surface or vector is not detailed in the supplied information, and it is inferred that an attacker with local kernel privileges would be required to exploit it.
OpenCVE Enrichment