drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
Prevent unauthorized termination of active GPU debug sessions.
Previously, users with /dev/kfd access could terminate another process's
debug session without proper ownership or ptrace authorization.
(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/4070909ac042f44654aac72f7986ea550c96f591https://git.kernel.org/stable/c/99b2fe4f19e3be0a8d0a0b5ea98d855970889653https://git.kernel.org/stable/c/9e52212aff8ed1fd9087728f61243ce3efd9d0achttps://git.kernel.org/stable/c/b8c05061997408bf81759f2dd31cd5f66771d15fhttps://git.kernel.org/stable/c/ce813614f63b020a826071276a92f2cfae7cba79