PT-2025-37605 · Linux+4 · Linux+4
CVE-2022-50303
·
Published
2022-01-01
·
Updated
2026-08-23
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A double-free issue exists in the
amdgpu amdkfd gpuvm acquire process vm() function within the drivers/gpu/drm/amd/amdgpu/amdgpu amdkfd gpuvm.c module. The problem occurs when kfd process device init vm() returns a failure after a virtual machine (vm) is converted to a compute vm and the vm->pasid is set to a compute pasid, but the KFD fails to take the pdd->drm file reference. This allows the drm close file handler to release the compute pasid before the KFD process destroy worker releases the same pasid and sets vm->pasid to zero, leading to a NULL pointer dereference and potential impacts on confidentiality, integrity, and availability of protected information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Debian
Linux
Red Hat
Suse