SB2024093044 - NULL pointer dereference in Linux kernel amd amdkfd driver
Published: September 30, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2024-46803)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the debug_event_write_work_handler() and kfd_dbg_trap_disable() functions in drivers/gpu/drm/amd/amdkfd/kfd_debug.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/e6ea3b8fe398915338147fe54dd2db8155fdafd8
- https://git.kernel.org/stable/c/820dcbd38a77bd5fdc4236d521c1c122841227d0
- https://git.kernel.org/stable/c/547033b593063eb85bfdf9b25a5f1b8fd1911be2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10.9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.50