CVE-2023-53009

MEDIUM

Linux Kernel - Data Corruption via Uninitialized VRAM Buffer Object

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add sync after creating vram bo There will be data corruption on vram allocated by svm if the initialization is not complete and application is writting on the memory. Adding sync to wait for the initialization completion is to resolve this issue.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 5.14.0 - 6.1.9linux
Linux/Linux < 5.14
Linux/Linux 42de677f79999791bee4e21be318c32d90ab62c6 - 92af2d3b57a1afdfdcafb1c6a07ffd89cf3e98fb
Linux/Linux 42de677f79999791bee4e21be318c32d90ab62c6 - ba029e9991d9be90a28b6a0ceb25e9a6fb348829
Linux/Linux 5.14
Linux/Linux 6.1.9 - 6.1.*
Linux/Linux 6.2
linux/linux_kernel 6.2 rc1 (3 CPE variants)
linux/linux_kernel 5.14 - 6.1.9
Published Mar 27, 2025
Tracked Since Feb 18, 2026