In the Linux kernel, the following vulnerability has been resolved:drm/amdgpu: fix possible UAF in amdgpu_cs_pass1()Since the gang_size check is outside of chunk parsingloop, we need to reset i before we free the chunk data.Suggested by Ye Zhang (@VAR10CK) of Baidu Security.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds