habanalabs kernel driver (Gaudi NIC queue validation): A shift-out-of-bounds in Gaudi NIC queue validation: the driver
Impact
A shift-out-of-bounds in Gaudi NIC queue validation: the driver computes a queue offset for queue types that are not NIC queues, producing undefined behaviour in the kernel. Practical effect is a kernel oops taking the node out of service; on a hardened kernel it is a panic.
Who can reach it
Local user with the habanalabs device node mapped in - i.e. any Gaudi tenant container.
What to do
Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.
References
Related entries
- GPU Display Driver (GeForce/RTX/Quadro/Tesla/vGPU): Info disclosure + DoS (OOB read in kernel driver)CVE-2023-0180 · GPU Display Driver (GeForce/RTX/Quadro/Tesla/vGPU)High
- GPU Display Driver: Local privesc / data tampering (missing access control)CVE-2023-0181 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (kernel buffer overflow)CVE-2023-0183 · GPU Display DriverHigh
- GPU Display Driver: Local privesc / data tampering (OOB write)CVE-2023-0191 · GPU Display DriverHigh
- NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko): An unprivileged user triggers an integer overflowCVE-2023-25516 · NVIDIA GPU Display Driver - Linux kernel module (nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): The vGPU plugin lets a guest OS controlCVE-2023-25517 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.