Impact
An out‑of‑bounds write occurs in the AMDGPU driver of the Linux kernel when the firmware (vBIOS) is updated. The vulnerable code fails to clamp the buffer position appropriately, permitting an attacker who can trigger a vBIOS update to overwrite kernel memory. Such corruption could allow arbitrary code execution or destabilize the kernel, leading to denial of service.
Affected Systems
The flaw resides in the Linux kernel’s drm/amdgpu driver and thus affects all Linux distributions that include the unpatched AMDGPU code. No specific kernel versions are listed, so any kernel build containing this driver logic prior to the commit referenced in the advisory is potentially impacted.
Risk and Exploitability
The CVSS score and EPSS are not available, and the vulnerability is not listed in CISA KEV, so the exact likelihood of exploitation is unknown. The flaw could be triggered only by an entity with the privilege to perform a vBIOS update, typically a local administrator or privileged user. If exploited, the out‑of‑bounds write could lead to code execution or system crash, indicating a high potential impact if the attack vector is attained.
OpenCVE Enrichment