Description
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix crash when destroying a suspended hardware context If userspace issues an ioctl to destroy a hardware context that has already been automatically suspended, the driver may crash because the mailbox channel pointer is NULL for the suspended context. Fix this by checking the mailbox channel pointer in aie2_destroy_context() before accessing it.
Product status
2611c9616cb52d3ed54a6095d72d18e645a6955a (git) before a6317704edab95d66a62fc1861d9546284ab678e
97f27573837ef96b4ba42af463cc800cab615c0e (git) before 8363c02863332992a1822688da41f881d88d1631
6.19.4 (semver) before 6.19.7
References
git.kernel.org/...c/a6317704edab95d66a62fc1861d9546284ab678e
git.kernel.org/...c/8363c02863332992a1822688da41f881d88d1631