
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-52624 is a vulnerability in the Linux kernel affecting the AMD display driver (drm/amd/display) component. The issue involves the DMCUB (Display Micro-Controller Unit B) interface, where attempting to interface with hardware through the GPINT mailbox while DMCUB is in idle state could result in system issues (Ubuntu Security).
The vulnerability occurs when attempting to execute GPINT commands while the DMCUB is in an idle state. The technical fix involves implementing a dc_wake_and_execute_gpint() function to properly manage the wake, execute, and sleep sequence. This function ensures that if the GPINT executes successfully, the DMCUB will be returned to sleep state after any optional response is returned, functioning similarly to the inbox command interface (Ubuntu Security).
When exploited, this vulnerability can lead to system hangs when attempting to interface with hardware through the GPINT mailbox while the DMCUB is in an idle state (Ubuntu Security).
The vulnerability has been addressed in newer kernel versions. Various Linux distributions have implemented fixes, with Ubuntu marking it as 'not affected' in versions 24.10 (oracular) and 24.04 LTS (noble), while older versions such as 22.04 LTS (jammy) and 20.04 LTS (focal) remain vulnerable pending updates (Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."