CVE-2023-53152 is a vulnerability in the Linux kernel's AMDGPU driver, specifically affecting the amddrm_buddy_fini function. It occurs when the driver is removed, leading to a call trace warning because certain Buffer Objects (BOs) allocated for the PSP (Platform Security Processor) are not properly freed. This issue impacts Linux kernel versions utilizing the AMDGPU driver. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), with an attack vector of Local, low attack complexity, and no user interaction required. The potential impact is a High availability loss (A:H), indicating that an attacker could cause a denial of service or system instability. The CWE-772 classification points to an improper cleanup of allocated resources. Currently, there is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.12, < 6.1.47CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.4.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.