Junglewise Threat Intelligence

CVE-2023-53753: Linux kernel out-of-bounds access in AMD display driver

CVE-2023-53753 · Severity: high · CVSS 7.8 · Published 2025-12-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD display driver contains a memory bounds checking error in GPIO register mapping. This flaw allows out-of-bounds array access that could cause system instability, crashes, or potential privilege escalation on systems running affected kernel versions.

Technical details

This vulnerability is a classic out-of-bounds array access in the DRM (Direct Rendering Manager) AMD display driver's GPIO register handling code. The vulnerable component maps GPIO registers from static arrays (ddc_shift and ddc_mask) in hardware factory code for DCN20, DCN30, and DCN32 GPU architectures. The root cause is that the code attempts to access array indices beyond the allocated bounds when handling VGA-related GPIO configuration. An attacker with local access or ability to trigger display driver operations can exploit this to read or write memory outside intended buffer boundaries, potentially leading to denial of service or privilege escalation. The fix, merged in March 2023, adds proper boundary checks by including VGA-specific mask and shift list entries to the affected arrays.

Affected products

  • Linux Linux kernel Versions prior to the fix (commit 9190d4a263264eabf715f5fc1827da45e3fdc247), approximately kernel 5.x through early 6.x

Timeline

  • 2025-12-08: disclosed
  • 2023-03-10: patched

References

Related threats