Impact
The vulnerability arises from the Linux kernel’s amdgpu driver, where two voltage indices derived from the VBIOS—vddInd and vddcInd—are used to index power‑management voltage lookup tables without validating that the indices fall within the bounds of the arrays. Because the bounds check is omitted, an out‑of‑range index can cause the driver to read or write beyond the intended memory region, leading to kernel memory corruption, system instability, or a crash. This is an array index validation flaw.
Affected Systems
The flaw resides in the amdgpu driver bundled with the Linux kernel; any Linux distribution that ships an unpatched kernel build containing the amdgpu powerplay component is vulnerable. No specific kernel version range is documented, so all releases that contain the vulnerable code path are at risk, regardless of distribution.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a moderate‑to‑high severity that could allow local privilege escalation or denial of service. The EPSS score of less than 1% points to a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation. While the description does not explicitly state the attack vector, the nature of the bug implies that a local attacker could trigger it by supplying a malicious VBIOS or by manipulating the driver during initialization; a supply‑chain attack that replaces the GPU firmware is also plausible. Given the low exploitation probability, it is unlikely that widespread attacks will occur before the patch is deployed.
OpenCVE Enrichment
Debian DLA
Debian DSA