CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's dma_fence_dedup_array() function, which incorrectly returns 1 when called with zero input, leading to potential dereferencing of uninitialized memory in the amdgpu_userq_wait_*() functions. This could result in undefined behavior or crashes, posing a risk primarily to systems utilizing the AMD GPU driver. Administrators and developers managing Linux environments with AMD hardware should prioritize applying the patch to mitigate potential instability and security issues.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: dma-fence: Make dma_fence_dedup_array() robust against 0-count input dma_fence_dedup_array() returns 1 when called with num_fences == 0: the for-loop body never executes, j stays at 0, and the final `return ++j` yields 1. This contradicts both the kernel-doc ("Return: Number of unique fences remaining in the array") and the natural expectation that 0 input gives 0 output. The caller __dma_fence_unwrap_merge() bails out via the `if (count == 0 || count == 1)` fast path and so is save. But amdgpu_userq_wait_*() could reach the dedup call with a zero local count and dereference an uninitialized fence slot in the array. Make the contract match the documentation by returning 0 early. This also skips an unnecessary sort() call on an empty array.