Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's AMD display driver has been addressed, which caused a page fault due to a mismatch in the maximum surface definition. The driver used two different values to define the maximum number of surfaces, leading to inconsistencies. This issue particularly affected users of the Cosmic distribution on AMD hardware that supports two overlay planes, following the introduction of cursor overlay mode. The vulnerability was characterized by a supervisor read access page fault in kernel mode, indicating a failure to properly manage memory access rights.
Exploitation of this vulnerability led to a page fault in the kernel, causing a disruption in normal processing and potentially allowing for further exploitation or instability.
The vulnerability can be reproduced on a system running the affected version of the Linux kernel with AMD graphics. Users may experience the page fault issue when applications attempt to use overlay planes, particularly after the cursor overlay mode has been activated. The page fault can be observed in the system logs, detailing the supervisor read access error in kernel mode, which is indicative of the vulnerability.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the documentation for the specific Linux distribution in use.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.