Executive brief
A vulnerability exists in the Linux kernel's AMD display driver that could allow a local user to crash the system. The issue occurs when the system fails to properly verify internal display connection data, leading to a system failure (NULL pointer dereference). This primarily impacts system availability, potentially causing a denial-of-service on affected Linux workstations or servers using AMD graphics.
Technical details
A NULL pointer dereference vulnerability exists in the amdgpu_dm_connector_atomic_check function within drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c. The root cause is the lack of validation for the return values of drm_atomic_get_new_connector_state() and drm_atomic_get_old_connector_state(), which can return NULL in certain edge cases. A local attacker with low privileges could potentially trigger this condition to cause a kernel panic (Denial of Service). The issue has been resolved by adding explicit NULL checks and returning -EINVAL if the states are missing. Patches have been backported to multiple stable kernel branches including 5.15.y, 6.1.y, 6.6.y, 6.12.y, and 6.16.y.
Affected products
- Linux Linux Kernel 4.15 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-09-05: disclosed
- 2025-09-05: advisory
- 2025-08-18: patched: Initial fix committed to mainline kernel tree.
References
- https://git.kernel.org/stable/c/07b93a5704b0b72002f0c4bd1076214af67dc661
- https://git.kernel.org/stable/c/0c1a486cbe6f9cb194e3c4a8ade4af2a642ba165
- https://git.kernel.org/stable/c/36a6b43573d152736eaf2557fe60580dd73e9350
- https://git.kernel.org/stable/c/6f860abff89417c0354b6ee5bbca188a233c5762
- https://git.kernel.org/stable/c/9c92d12b5cb9d9d88c12ae71794d3a7382fcdec0
- https://git.kernel.org/stable/c/f653dd30839eb4f573a7539e90b8a58ff9bedf2f
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html