Impact
The Linux amdkfd driver allocates kernel buffers to return buffer object metadata in response to the AMDKFD_IOC_GET_DMABUF_INFO ioctl. The size of the buffer to allocate was previously controlled by the user. A malicious render‑group user could supply an enormous value, such as 2 GiB, causing the driver to reserve that amount of kernel memory, potentially exhausting system memory and triggering an out‑of‑memory condition. The patch changes the driver to first compute the required metadata size and, only if the actual size is within that limit, allocate a buffer and copy the data. If the requested size exceeds the limit, the driver returns an error instead of allocating.| This prevents hostile user input from causing massive kernel memory consumption.| The vulnerability is a classic case of uncontrolled memory allocation—but in kernel context—posing an availability impact rather than confidentiality or integrity.
Affected Systems
The affected software is the Linux kernel itself, specifically the amdkfd DRM driver module that handles AMD GPU compute device memory management. No specific kernel version ranges are listed in the advisory. Any system running a Linux kernel where the amdkfd driver is compiled and exported for use by render‑group users could be impacted.
Risk and Exploitability
Because the flaw requires a user in a render‑group to issue the ioctl, the attack vector is local to systems where such users exist. The exploit does not grant privilege escalation or data disclosure; it merely forces the kernel to allocate an attacker‑specified buffer size. While a CVSS score is not available in the advisory, the potential for a kernel out‑of‑memory attack makes the risk significant for availability, especially on systems with limited memory or many concurrent render‑group users. The advisory notes that EPSS data is not provided and that the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment