PT-2025-37605 · Linux+4 · Linux+4

CVE-2022-50303

·

Published

2022-01-01

·

Updated

2026-08-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double-free issue exists in the amdgpu amdkfd gpuvm acquire process vm() function within the drivers/gpu/drm/amd/amdgpu/amdgpu amdkfd gpuvm.c module. The problem occurs when kfd process device init vm() returns a failure after a virtual machine (vm) is converted to a compute vm and the vm->pasid is set to a compute pasid, but the KFD fails to take the pdd->drm file reference. This allows the drm close file handler to release the compute pasid before the KFD process destroy worker releases the same pasid and sets vm->pasid to zero, leading to a NULL pointer dereference and potential impacts on confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-71347
BDU:2026-06080
CESA-2023_7077
CVE-2022-50303
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:03615-1
SUSE-SU-2025:3761-1

Affected Products

Centos
Debian
Linux
Red Hat
Suse