Impact
The flaw in the Linux kernel’s AMD DRM powerplay driver occurs when a VoltageObjectInfo table supplied by the VBIOS does not validate its usSize field. A malformed table whose usSize is smaller than the header or would move the cursor past the table end triggers a zero‑stride loop or causes the driver to read beyond the heap boundary. This results in either a denial‑of‑service by an infinite loop or an out‑of‑bounds read that could expose private kernel memory. The affected code path can therefore be used by a hostile firmware author to compromise kernel confidentiality or availability.
Affected Systems
All Linux kernel builds that include the drm/amd/powerplay code before the commit fixing the loop are vulnerable. The vendor information lists Linux:Linux, indicating that every distribution shipping the stock kernel is potentially impacted. No specific kernel version range is listed, so any release that has not yet integrated the fix remains at risk.
Risk and Exploitability
The EPSS score for this vulnerability is reported as less than 1 % and it is not included in the CISA KEV catalog, suggesting a low probability of widespread exploitation. However, the flaw is locally exploitable from a malicious or corrupted VBIOS; an attacker who can supply a tainted firmware image to the GPU can trigger the out‑of‑bounds read or infinite loop. Once invoked, the impact is confined to the kernel, which may lead to data leakage or system instability.
OpenCVE Enrichment