CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's amdgpu driver, where user-supplied input for the number of entries can lead to excessive memory allocation, potentially causing a kernel panic on systems configured to panic on warnings. This issue could be exploited to disrupt system stability and should be prioritized by organizations using affected Linux distributions and F5 products, particularly those running configurations that enable panic on warnings. Immediate remediation is recommended to prevent potential denial-of-service scenarios.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO kvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERNEL) at amdgpu_gem.c:1050 uses the user-supplied num_entries directly without any upper bounds check. Since num_entries is a __u32 and sizeof(drm_amdgpu_gem_vm_entry) is 32 bytes, a large num_entries produces an allocation exceeding INT_MAX, triggering WARNING in __kvmalloc_node_noprof(), causing a kernel WARNING, TAINT_WARN, and panic on CONFIG_PANIC_ON_WARN=y systems. Add a size bounds check before we invoke the kvzalloc() to reject oversized num_entries early with -EINVAL. (cherry picked from commit 1fe7bf5457f6efd7be60b17e23163ba54341d73d)