Executive brief
The Linux kernel's AMD display driver has a race condition during device removal that can cause the system to crash. When the display hardware is being shut down, I2C adapters (used for communication with display-connected devices) may still be accessible to user applications. If an I2C operation occurs after internal display state has been torn down, the kernel crashes with a NULL pointer dereference. This affects systems with AMD graphics during device removal or driver unload.
Technical details
This is a race condition (CWE-362) in the AMD display manager's I2C adapter teardown sequence in the Linux kernel's DRM subsystem. The vulnerable component is the amdgpu_dm_i2c_xfer() function in drivers/gpu/drm/amd/display/amdgpu_dm/. The vulnerability occurs because I2C adapters remain visible to userspace via the i2c-dev interface while DM (display manager) teardown is in progress. A concurrent i2c-dev transfer initiated via ioctl can enter amdgpu_dm_i2c_xfer() after backing DM structures have been freed, causing a NULL pointer dereference. The fix uses devres groups to ensure I2C adapters are removed and in-flight transfers drain before DM state is torn down during dm_hw_fini(). No authentication is required; local unprivileged users can trigger this via /dev/i2c-* device access. The patch is available and has been merged into Linux stable.
Affected products
- Linux Linux kernel versions prior to fix commit e4ae30a12aa95942814957d8bc1ce7366a7107d7
Timeline
- 2026-09-17: disclosed
- 2026-06-29: patched: Patch authored by Geoffrey McRae