CVE-2023-52817 is a moderate-severity flaw in the Linux kernel's AMDGPU DRM driver. On affected GPUs, including VEGA20, a low-privileged local user can read the amdgpu_regs_smc debugfs file while the smc_rreg pointer is NULL, triggering a NULL-pointer dereference in amdgpu_debugfs_regs_smc_read and causing a kernel oops or system crash. Red Hat rates the local denial-of-service issue CVSS 3.1 5.5.
The vulnerability is fixed in Linux stable releases 4.19.300, 5.4.262, 5.10.202, 5.15.140, 6.1.64, 6.5.13, 6.6.3, and 6.7 and later. Red Hat issued standard-kernel fixes for RHEL 8 and RHEL 9, plus the RHEL 8 real-time kernel, through advisories including RHSA-2024:7000, RHSA-2024:7001, and RHSA-2024:9315; RHEL 9 kernel-rt was listed as affected. Administrators should deploy the latest vendor-supported kernel update rather than backporting individual patches.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 standard kernel and RHSA-2024:7001 for the RHEL 8 real-time kernel, addressing CVE-2023-52817.
Mauro Matteo Cascella reported Red Hat bug 2282676 for CVE-2023-52817. Red Hat classified the issue as medium severity and medium priority.
Red Hat released RHSA-2024:2394 to fix CVE-2023-52817 in the standard Red Hat Enterprise Linux 9 kernel.
Red Hat released RHSA-2024:9315 as an additional fixed erratum for the RHEL 9 kernel vulnerability CVE-2023-52817.
The Linux kernel CVE team assigned CVE-2023-52817 to an AMDGPU DRM debugfs NULL-pointer dereference that can be triggered by reading amdgpu_regs_smc on affected GPUs, including VEGA20.
The NULL-pointer dereference was fixed in Linux kernel versions 4.19.300, 5.4.262, 5.10.202, 5.15.140, 6.1.64, 6.5.13, 6.6.3, and 6.7. The fixes prevent an AMDGPU debugfs read from dereferencing a NULL smc_rreg pointer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.