Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-40339

Опубликовано: 09 дек. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.

A NULL pointer dereference flaw was found in the Linux kernel's AMD GPU (amdgpu) driver. In the amdgpu_vm_handle_moved() function, when processing amdgpu_bo_va entries that are part of fpriv->prt_va (partially resident texture virtual address), the associated buffer object (bo) is always NULL. Dereferencing this NULL pointer causes a kernel crash. A local user with access to AMD GPU resources could trigger this condition, resulting in a denial of service.

Отчет

This vulnerability affects systems with AMD GPUs using the amdgpu driver. Exploitation requires local access and the ability to interact with AMD GPU virtual memory management. The impact is limited to denial of service through a kernel crash.

Меры по смягчению последствий

To mitigate this issue, prevent the amdgpu module from being loaded if AMD GPU functionality is not required. See https://access.redhat.com/solutions/41278 for instructions on how to blacklist a kernel module.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2420421kernel: drm/amdgpu: fix nullptr err of vm_handle_moved

EPSS

Процентиль: 7%
0.00025
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.

nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.

msrc
3 месяца назад

drm/amdgpu: fix nullptr err of vm_handle_moved

debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: d ...

github
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.

EPSS

Процентиль: 7%
0.00025
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2025-40339