The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade SLES:16.0.0 kernel-docs-html to version 6.12.0-160000.9.1 or higher.
Note: Versions mentioned in the description apply only to the upstream kernel-docs-html package and not the kernel-docs-html package as distributed by SLES.
See How to fix? for SLES:16.0.0 relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices
Previously, APU platforms (and other scenarios with uninitialized VRAM managers)
triggered a NULL pointer dereference in ttm_resource_manager_usage(). The root
cause is not that the struct ttm_resource_manager *man pointer itself is NULL,
but that man->bdev (the backing device pointer within the manager) remains
uninitialized (NULL) on APUs—since APUs lack dedicated VRAM and do not fully
set up VRAM manager structures. When ttm_resource_manager_usage() attempts to
acquire man->bdev->lru_lock, it dereferences the NULL man->bdev, leading to
a kernel OOPS.
amdgpu_cs.c: Extend the existing bandwidth control check in
amdgpu_cs_get_threshold_for_moves() to include a check for
ttm_resource_manager_used(). If the manager is not used (uninitialized
bdev), return 0 for migration thresholds immediately—skipping VRAM-specific
logic that would trigger the NULL dereference.
amdgpu_kms.c: Update the AMDGPU_INFO_VRAM_USAGE ioctl and memory info
reporting to use a conditional: if the manager is used, return the real VRAM
usage; otherwise, return 0. This avoids accessing man->bdev when it is
NULL.
amdgpu_virt.c: Modify the vf2pf (virtual function to physical function)
data write path. Use ttm_resource_manager_used() to check validity: if the
manager is usable, calculate fb_usage from VRAM usage; otherwise, set
fb_usage to 0 (APUs have no discrete framebuffer to report).
This approach is more robust than APU-specific checks because it:
man->bdev and pass the ttm_resource_manager_used() check).v4: use ttm_resource_manager_used(&adev->mman.vram_mgr.manager) instead of checking the adev->gmc.is_app_apu flag (Christian)