CVE-2023-53545

Description

A locking violation was found in the Linux kernel's AMD GPU driver in the context save area cleanup path. A local user can trigger this issue when closing GPU contexts, causing the driver to unmap and remove virtual memory mappings without first reserving the root page directory buffer object. This violates kernel locking rules and triggers lockdep warnings, potentially leading to system instability and denial of service.

Statement

AMD GPUs use a context save area (CSA) to preserve GPU state across context switches. When a process closes its GPU file descriptor, the cleanup code needs to unmap the CSA virtual address and remove it from the GPU's virtual memory system. The amdgpu_vm_bo_del function—which handles this unmapping—requires that the root page directory BO be reserved (locked) before it can safely modify the VM structure. However, the cleanup path in amdgpu_driver_postclose_kms was calling this function without holding the required lock. This creates a race condition window where concurrent GPU operations could be accessing the same VM structures. Lockdep immediately catches this violation and emits warnings. While the immediate symptom is warning messages, the underlying race could cause memory corruption or use-after-free conditions.

Mitigation

To mitigate this issue, prevent the amdgpu module from being loaded. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.55.57.8
Attack VectorLocalLocalLocal
Attack ComplexityLowLowLow
Privileges RequiredLowLowLow
User InteractionNoneNoneNone
ScopeUnchangedUnchangedUnchanged
ConfidentialityNoneNoneHigh
Integrity ImpactNoneNoneHigh
Availability ImpactHighHighHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Other

Technical Impact: Alter Execution Logic; Unexpected State

The main problem is that -- if a lock is overcome -- data could be altered in a bad state.

Frequently Asked Questions

Want to get errata notifications? Sign up here.