Linux Kernel Null Pointer Dereference Vulnerability in AMD GPU Driver

Vulnerability

A null pointer dereference vulnerability has been identified in the Linux kernel's AMD GPU driver component, specifically within the Direct Rendering Manager (DRM) and AMD Kernel Fusion Driver (AMDKFD) areas. The issue arises because the kmalloc_array() function can return null, leading to a potential dereference of a null pointer in 'event_waiters[i].wait'. This vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability leads to a null pointer dereference, causing a kernel crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.