CVE-2022-3108 describes a vulnerability in the Linux kernel, specifically affecting versions through 5.16-rc6, where the kfd_parse_subtype_iolink function in the AMDGPU driver fails to check the return value of kmemdup(). This oversight can lead to a denial-of-service condition. With a CVSS score of 5.5 (Medium), this local vulnerability requires low privileges and has a low attack complexity, potentially causing high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.16.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.16.0:-:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.16.0:rc1:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.16.0:rc2:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.16.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
An issue was discovered in the Linux kernel through 5.16-rc6. kfd_parse_subtype_iolink in drivers/gpu/drm/amd/amdkfd/kfd_crat.c lacks check of the return value of kmemdup().
Dec 13, 2022kernel: drm/amdkfd: NULL pointer dereference in kfd_parse_subtype_iolink()
Dec 13, 2022