Bug 2241909 (CVE-2023-20598)

Summary: CVE-2023-20598 hw: amd: AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability
Product: [Other] Security Response Reporter: Rohit Keshri <rkeshri>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: acaringi, allarkin, bhu, chwhite, dbohanno, debarbos, dvlasenk, ezulian, hkrzesin, jarod, jfaracco, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, ldoskova, lgoncalv, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, scweaver, security-response-team, tglozar, wcosta, williams, wmealing, ycote, ykopkova
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
An improper privilege management flaw was found in the AMD RadeonTM Graphics driver. This issue may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses, resulting in potential arbitrary code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2241225    

Description Rohit Keshri 2023-10-03 11:10:02 UTC
The AMD kernel driver (pdfwkrnl.sys), which is part of the IO device controller (USB-C device)
firmware update utility, is intended to be executed only by a privileged user (i.e., an administrator) on
the target system when updating the AMD RadeonTM Software (Adrenalin Edition and PRO
Edition). However, the improper privilege management vulnerability may allow a low-privileged user
to launch an attack while a privileged user is running the firmware update utility tool because the
firmware update utility requires exposing the IOCTL interface to perform the firmware update process.
During this IOCTL exposure, the low privileged user could potentially gain I/O control of the USB ports
or physical addresses, exploiting the improper privilege management vulnerability

Refer:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6009.html