Database/Kernel, userspace & hypervisor
Linux i915 GPU kernel driver (TLB invalidation): An incorrect TLB flush in i915 leaves the GPU able to reach memory it
Impact
An incorrect TLB flush in i915 leaves the GPU able to reach memory it should no longer see, producing random memory corruption or leakage across contexts. Same family as the earlier GTT TLB bug and with the same consequence for a shared GPU node: one tenant's GPU reads or corrupts pages that now belong to someone else.
Who can reach it
Any local user or container with a DRM render node - i.e. any tenant that was scheduled a GPU. No privileged capability needed.
What to do
Kernel update and reboot. Drain the node first. No firmware or microcode component; the fix is entirely in the driver's invalidation logic.
References
Related entries
- Xen (shadow paging): x86 shadow plus log-dirty mode use-after-free - guest to hostCVE-2022-42332 · Xen (shadow paging)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2022-48662 · Linux i915 GPU kernel driverHigh
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theCVE-2022-48721 · Linux kernel (net/smc)High
- Linux kernel (drivers/gpu/drm/vmwgfx): When the copy of the fence reply back to userspace fails, the driver installs aCVE-2022-48771 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): User-resource lookup during command submission used a broken RCU fast path, soCVE-2022-48887 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/virtio): GEM handle values are guessable, and the driver dereferences the buffer objectCVE-2022-48899 · Linux kernel (drivers/gpu/drm/virtio)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.