Executive brief
The AMD KFD (Kernel Fusion Driver) component in the Linux kernel contains a memory management bug that can cause memory leaks and segmentation faults when importing DMA buffers for GPU operations. An attacker or malfunctioning user-space application could trigger this condition to exhaust system memory or crash the kernel, affecting system stability and availability.
Technical details
This vulnerability is a memory leak and use-after-free bug in the `_gpuvm_import_dmabuf()` function of the AMD KFD driver (amdgpu). The root cause is an incorrect call to `kfree(mem)` instead of `kfree(*mem)` in the error handling path when `drm_vma_node_allow()` fails. This results in freeing the wrong memory location and leaking the actual allocation, potentially causing a segmentation fault. The fix is a one-line change correcting the pointer dereference. The vulnerability is local to the host and requires the ability to invoke the affected code path, typically through unprivileged GPU operations. A patch was committed upstream in November 2022.
Affected products
- Linux Linux Kernel affected versions in amdgpu amdkfd driver (prior to commit 75818afff631e1ea785a82c3e8bb82eb0dee539c)
Timeline
- 2022-11-28: disclosed: Patch committed upstream
- 2022-11-29: patched: Fix merged in AMD branch
- 2025-10-07: advisory: CVE-2022-50528 published