habanalabs kernel driver (gaudi_memset_device_memory): Use-after-free in the Gaudi device-memory memset path
Impact
Use-after-free in the Gaudi device-memory memset path: the command buffer is released on the error path and then dereferenced again. Gives a local accelerator user a kernel UAF - crash at minimum, and the usual UAF privilege-escalation potential with enough heap grooming.
Who can reach it
Local user holding the habanalabs device node, reached by driving the memset ioctl down an error path.
What to do
Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdgpu): A use-after-free in the amdkfd (KFD compute driverCVE-2021-47142 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdgpu)High
- NVIDIA/Mellanox ConnectX driver (mlx5_ib completion-queue resize, init_cq_frag_buf): CQ resize initialised the wrongCVE-2021-47261 · NVIDIA/Mellanox ConnectX driver (mlx5_ib completion-queue resize, init_cq_frag_buf)High
- Linux kernel amdgpu kernel driver core (drm/amdgpu): A race condition or locking defect in the amdgpu kernel driverCVE-2021-47421 · Linux kernel amdgpu kernel driver core (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amdgpu): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2021-47489 · Linux kernel amdgpu display core (DC/DM) (drm/amdgpu)High
- NVIDIA CUDA Toolkit - cuobjdump: An integer overflow reached by disassembling a corrupted fatbin gives remote codeCVE-2022-21821 · NVIDIA CUDA Toolkit - cuobjdumpHigh
- NVIDIA GPU Display Driver - Windows kernel mode layer (nvlddmkm.sys): Missing data validation lets a basic user causeCVE-2022-31606 · NVIDIA GPU Display Driver - Windows kernel mode layer (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.