CVE-2023-52657
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-52657 affects the Linux kernel's AMD graphics driver. The vulnerability was discovered when a previous fix for a reboot exception in the SI Oland graphics card caused system hangs when Display Core (DC) was enabled and errors during driver reboot and power off cycles (Kernel Git). The issue was resolved by reverting commit e490d60a2f76bff636c68ce4fe34c1b6c34bbd86.

Technical details

The vulnerability is related to the AMD graphics driver's power management functionality in the Linux kernel, specifically affecting the SI (Southern Islands) series graphics cards when using the Display Core feature. The issue manifests in the legacy DPM (Dynamic Power Management) code for SI devices, particularly in the temperature range setting functionality (Kernel Git). Red Hat has assigned this vulnerability a CVSS v3 base score of 5.5 with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Impact

The vulnerability can cause system hangs when Display Core (DC) is enabled on affected AMD SI series graphics cards. Additionally, it can lead to errors during driver reboot and power off cycles, potentially affecting system stability and normal operation (Kernel Git).

Exploitability

The vulnerability requires local access and low privileges to exploit. It primarily affects systems running AMD SI series graphics cards with Display Core enabled (Red Hat).

Mitigation and workarounds

The issue has been addressed by reverting the problematic commit (e490d60a2f76bff636c68ce4fe34c1b6c34bbd86) in the Linux kernel. Users should update to kernel versions that include this reversion to resolve the vulnerability (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74730CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 22, 2026
CVE-2026-74733HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 22, 2026
CVE-2026-74726HIGH7.3
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesAug 22, 2026
CVE-2026-74732MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-selftests-internal
NoYesAug 22, 2026
CVE-2026-74728NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-modules-core
NoNoAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management