Database/Kernel, userspace & hypervisor
AMD Radeon Kernel Mode driver - Escape 0x2000c00 call handler: A low-privileged attacker can drive the Radeon
Impact
A low-privileged attacker can drive the Radeon kernel-mode driver's Escape 0x2000c00 handler into privilege escalation or denial of service. Escape call handlers are the driver's catch-all ioctl surface and historically its weakest - a low-privilege caller reaching kernel-mode escalation is the pattern that makes GPU device nodes dangerous to hand out.
Who can reach it
Local, low privilege - reachable by an ordinary user with the GPU device open.
What to do
Update the AMD graphics driver and reload or reboot. Note this is the Windows kernel-mode driver surface; Linux ROCm fleets are not affected by this specific handler, though the lesson about escape/ioctl surfaces carries over.
References
Related entries
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2020-7053 · Linux i915 GPU kernel driverHigh
- Linux kernel (netfilter x_tables): Heap out-of-bounds write in xt_compat_target_from_user()CVE-2021-22555 · Linux kernel (netfilter x_tables)High
- sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountCVE-2021-3156 · sudoHigh
- Linux kernel (seq_file / fs layer): Sequoia: size_t-to-int conversion in the filesystem layer, local root on defaultCVE-2021-33909 · Linux kernel (seq_file / fs layer)High
- Linux kernel (eBPF verifier): eBPF ALU32 bitwise-op bounds tracking flawCVE-2021-3490 · Linux kernel (eBPF verifier)High
- polkit: Local privilege escalation via polkit_system_bus_name_get_creds_sync() raceCVE-2021-3560 · polkitHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.