Impact
The vulnerability arises from a missing bounds check on voltage index tables in the Linux amdgpu driver’s powerplay subsystem. Indices parsed from the VBIOS are used to look up voltage settings without verifying that they fall within the bounds of the corresponding lookup tables. When an out‑of‑range index is supplied the driver returns –EINVAL, which can cause the GPU power‑management functions to fail or hang. The weakness is an out‑of‑bounds memory access and the impact is a denial of service to the GPU power‑management path. Based on the description, the likely attack vector requires local access to the system’s GPU firmware; installing a crafted or maliciously signed VBIOS image could trigger the failure.
Affected Systems
Linux kernel distributions that ship the amdgpu driver and contain the vulnerable powerplay code. Any kernel version prior to the patched release is affected; the exact affected build numbers are not specified in the data. They correspond to the Linux:Linux vendor/product pair.
Risk and Exploitability
The single‑point failure caused by the unchecked voltage index can lead to a GPU driver crash or a deadlock in power‑management, effectively interrupting GPU availability and potentially the broader system if the driver is essential. The CVSS score of 7.3 indicates a high severity. With a VBIOS image under the attacker’s control, local exploitation is feasible. However, the very low EPSS score (<1%) and the absence from KEV suggest that exploitation is unlikely in the wild at this time, but the inherent local nature of the attack means readiness to mitigate is prudent.
OpenCVE Enrichment
Debian DLA
Debian DSA