PT-2025-40687 · Amd+4 · Amdgpu+4

Published

2024-04-30

·

Updated

2026-05-26

·

CVE-2023-53545

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue was identified in the Linux kernel related to the handling of memory management within the DRM/amdgpu subsystem. Specifically, the vulnerability concerns the improper unmapping and removal of a csa va (color space array virtual address). The root page directory BO (BO = buffer object) should be reserved before unmapping and removing a bo va (buffer object virtual address) from the virtual memory area to prevent lock dependency issues. A warning message was observed in the kernel logs during testing, indicating a potential problem in the amdgpu vm bo del function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

ALSA-2025_16880
AZL-77432
CVE-2023-53545
ECHO-30F2-89F7-6C0A
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Affected Products

Debian
Linux Kernel
Red Hat
Suse
Amdgpu