CyberRota Analysis
AI-GeneratedA potential time-of-check to time-of-use (TOCTOU) vulnerability exists in the Linux kernel's AMD GPU driver, specifically related to the handling of the parameter length in the video coding engine. This flaw could allow an attacker to exploit changes in the instruction buffer (IB) contents between reads, potentially leading to unauthorized access or manipulation of data. Organizations using affected Linux distributions with AMD GPU hardware should prioritize applying the relevant updates to mitigate this risk.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)