GPU VulnDB

Database/NVIDIA / GPU stack

habanalabs kernel driver (Gaudi NIC queue validation): A shift-out-of-bounds in Gaudi NIC queue validation: the driver

CVE-2022-50026NVIDIA / GPU stackcurated

Impact

A shift-out-of-bounds in Gaudi NIC queue validation: the driver computes a queue offset for queue types that are not NIC queues, producing undefined behaviour in the kernel. Practical effect is a kernel oops taking the node out of service; on a hardened kernel it is a panic.

Who can reach it

Local user with the habanalabs device node mapped in - i.e. any Gaudi tenant container.

What to do

Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.