
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53806 is a Linux kernel vulnerability in the drm/amd/display subsystem where the SubVP (Sub-Viewport) command info population routine incorrectly processes both display pipes instead of only the top pipe, leading to an out-of-bounds array access and system page fault. The vulnerability manifests as a system restart when changing display resolution to 8K in extended mode. It affects the Linux kernel across multiple stable branches, with patches available for versions 6.1.30, 6.3.4, and 6.4. The CVSS base score is estimated as Medium, with an EPSS score of approximately 0.017% (Feedly, ENISA EUVD).
The root cause is an out-of-bounds array access (CWE-125) in the AMD Display driver's SubVP command info population logic within the Linux kernel's DRM subsystem. When the driver populates SubVP (Sub-Viewport) information, it incorrectly iterates over both primary and secondary display pipes using vblank data, rather than restricting the operation to the top pipe only. This causes the array index to exceed its valid bounds when a second pipe is processed, triggering a kernel page fault. The fix adds a conditional check to ensure only the top pipe is used when populating SubVP command info, preventing the out-of-bounds access (Feedly, ENISA EUVD).
Exploitation of this vulnerability results in a kernel page fault that causes an immediate system restart, representing a complete availability impact for the affected system. The vulnerability is triggered locally by a user with access to display configuration (e.g., changing resolution to 8K in extended/multi-monitor mode), and does not appear to offer a path to code execution or data exfiltration based on available information. There is no known impact to confidentiality or integrity beyond the denial-of-service caused by the system crash (Feedly).
There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2023-53806. The vulnerability requires local access and specific hardware (AMD GPU with SubVP support) and a display configuration change to 8K extended mode to trigger. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
The Linux kernel maintainers have released patches for the affected stable branches: version 6.1.30, 6.3.4, and 6.4 include the fix. Users running affected kernel versions with AMD GPUs should update to a patched kernel release. As a temporary workaround, avoiding 8K resolution in extended display mode on affected AMD GPU hardware can prevent triggering the page fault until a kernel update is applied (ENISA EUVD, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."