CVE-2024-36022: drm/amdgpu: Init zone device and drm client after mode-1 reset on reload

Published May 30, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Init zone device and drm client after mode-1 reset on reload

In passthrough environment, when amdgpu is reloaded after unload, mode-1 is triggered after initializing the necessary IPs, That init does not include KFD, and KFD init waits until the reset is completed. KFD init is called in the reset handler, but in this case, the zone device and drm client is not initialized, causing app to create kernel panic.

v2: Removing the init KFD condition from amdgpuamdkfddrmclientcreate. As the previous version has the potential of creating DRM client twice.

v3: v2 patch results in SDMA engine hung as DRM open causes VM clear to SDMA before SDMA init. Adding the condition to in drm client creation, on top of v1, to guard against drm client creation call multiple times.

Other sources

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Init zone device and drm client after mode-1 reset on reload

The Linux kernel CVE team has assigned CVE-2024-36022 to this issue.

Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024053013-CVE-2024-36022-fe0e@gregkh/T

Red Hat

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

NVD

Affected Software

3 affected componentsFixes available
redhat/kernel<6.8.6
6.8.6
redhat/kernel<6.9
6.9
debian/linux<=5.10.223-1, <=5.10.234-1, <=6.1.129-1, <=6.1.133-1
6.12.22-16.12.25-1

Event History

May 30, 2024
CVE Published
via MITRE·03:03 PM
Rejected
via MITRE·03:03 PM
Data Sourced
via NVD·03:15 PM
Description
Jun 3, 2024
Data Sourced
via Red Hat·08:54 AM
DescriptionSeverityAffected Software
Jul 15, 2024
Data Sourced
via Launchpad·07:50 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·12:25 AM
RemedyDescriptionSeverityAffected Software
Jun 19, 2025
Rejected
via MITRE·01:03 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-36022?

CVE-2024-36022 has a high severity rating due to its implications for device function and potential system crashes.

2

What software versions are affected by CVE-2024-36022?

CVE-2024-36022 affects kernel versions up to 6.8.6 and 6.9 for Red Hat, as well as multiple Debian kernel versions up to 6.1.123-1.

3

How do I fix CVE-2024-36022?

To fix CVE-2024-36022, upgrade to the patched versions of the kernel specified in the references, including Red Hat's 6.8.6 and 6.9 or Debian's 5.10.223-1, 5.10.226-1, 6.1.123-1, or 6.1.119-1.

4

Is there a exploit or proof of concept available for CVE-2024-36022?

As of now, there are no publicly known exploits or proof of concept code for CVE-2024-36022.

5

What is the impact of CVE-2024-36022 on system performance?

CVE-2024-36022 can lead to performance degradation or failures in the GPU handling and overall system stability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203