Security readout for executives and security teams
Plain-English summary
A Linux AMD GPU recovery flaw can perform an unnecessary second PCI reset, causing a kernel fault or system hang during repeated hardware-error recovery. The clearest demonstrated risk is operational disruption on affected AMD GPU systems; the supplied evidence does not demonstrate a remote attack.
Executive priority
Treat as a high-priority reliability issue for affected AMD GPU compute or multi-GPU systems, especially where downtime is costly. Prioritize targeted inventory and vendor-supported kernel updates. General Linux fleets without AMDGPU exposure are unlikely to share the documented trigger conditions.
Technical view
During AMDGPU RAS fatal-error recovery, a mode-1 reset already covers every node in the GPU hive. A subsequent PCI error slot reset can trigger another mode-1 reset, leading to a general protection fault and hang. The supplied CVSS is 7.8 with a local, low-privilege vector.
Likely exposure
Exposure is limited to Linux systems using AMDGPU where the affected RAS recovery path can occur, particularly relevant multi-GPU or error-recovery environments. The bundle's version entries are ambiguous, listing 4.2, 6.8.6, and 6.9 without clear distribution-package boundaries; confirm status with the operating-system vendor.
Exploitation context
The supplied bundle reports no CISA KEV listing and provides no evidence of active exploitation. Its CVSS vector describes local access, low complexity, low privileges, and no user interaction. The documented failure followed repeated UMC uncorrectable-error injection, so real-world reachability outside specialized GPU environments remains unclear.
Researcher notes
The directly demonstrated outcome is a general protection fault and hang during RAS recovery. Although CVSS models high confidentiality, integrity, and availability impacts, the supplied technical narrative primarily substantiates availability loss. Exact affected and fixed distribution versions, practical trigger accessibility, and exploitation prevalence are not established in the bundle.
Mitigation direction
Inventory Linux systems using AMDGPU and compare installed kernel packages with vendor advisories for this CVE.
Upgrade to a vendor-supported kernel incorporating the applicable cited stable fix.
Prioritize AMD GPU systems using RAS or multi-GPU hive configurations.
Monitor distribution guidance for explicit fixed package versions.
Validation and detection
Verify whether AMDGPU and relevant AMD GPU hardware are present.
Confirm the installed kernel changelog identifies this CVE or the applicable cited fix.
Review kernel logs for GPU resets, PCI slot resets, hangs, or general protection faults.
After updating, confirm the vendor package version and normal GPU recovery behavior.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-35931 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.