krnel Module Fixes Possible UAF in amdgpu Code
CVE-2023-52921

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2023-52921?

The vulnerability in the Linux kernel pertains to a use-after-free issue within the AMD graphics driver, specifically in the amdgpu_cs_pass1 function. The gang_size check is incorrectly placed outside of the chunk parsing loop, which may lead to improper handling of the chunk data when freed. This flaw was brought to attention by security researcher Ye Zhang from Baidu Security and has been addressed in subsequent kernel updates. Users relying on AMD GPUs are urged to ensure their systems are updated to mitigate potential risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 2ebf61f2cfb9a11bc17db30df3e675a4cd7418d3

Linux 2ebf61f2cfb9a11bc17db30df3e675a4cd7418d3 < 90e065677e0362a777b9db97ea21d43a39211399

Linux 6.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.