Executive brief
A vulnerability exists in the Linux kernel's AMD GPU driver that could lead to a system crash or unauthorized memory access. The issue occurs during GPU error recovery, where a race condition allows the system to attempt to use data that has already been deleted from memory. This could impact the stability of systems using AMD graphics hardware and potentially be exploited to compromise the operating system.
Technical details
A use-after-free (UAF) vulnerability exists in 'drivers/gpu/drm/amd/amdgpu/amdgpu_device.c' within the Linux kernel. The flaw is rooted in a race condition during GPU recovery: 'amdgpu_device_gpu_recover' calls 'drm_sched_start', which restarts the TDR (Timeout Detection and Recovery) queue. If the TDR queue frees a job before the timeout callback finishes its execution, the kernel attempts to access the 'pasid' field of the now-freed job structure. Local attackers could potentially exploit this to cause a kernel panic (DoS) or achieve local privilege escalation. The fix involves caching the 'pasid' early in the recovery process to avoid accessing the job structure after it may have been freed. Patches are available in stable kernel releases including 6.18.3 and 6.19.
Affected products
- Linux Linux Kernel 6.17 to 6.18.3
Timeline
- 2025-12-10: patched: Initial fix commit by Alex Deucher
- 2026-01-13: disclosed: CVE published