Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A null pointer dereference vulnerability has been identified in the Linux kernel's AMD GPU power management component. This issue arises when a string is written to the 'gpu_od/fan_ctrl' sysfs interface or the 'pp_power_profile_mode' setting for the CUSTOM profile, without proper delimiters. The vulnerability is present in the Linux kernel stable tree.
Exploitation of this vulnerability leads to a null pointer dereference, causing a crash or denial of service condition.
To reproduce this vulnerability, write a string without delimiters to the 'gpu_od/fan_ctrl' sysfs interface or the 'pp_power_profile_mode' for the CUSTOM profile. The absence of delimiters will trigger the null pointer dereference.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.