Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/i915/gt): Compression (CCS) metadata attached to local memory was not cleared when the
Impact
Compression (CCS) metadata attached to local memory was not cleared when the memory was handed to a new owner, so a tenant receiving recycled VRAM inherits the previous tenant's compression state. The upstream fix is worded exactly that way - the kernel was leaking the CCS state from the previous user - which is residual-data exposure across workloads sharing a discrete Intel GPU.
Who can reach it
A tenant container holding /dev/dri/renderD* on a discrete Intel GPU allocates local memory that a previous tenant freed and reads it back with the compression state still attached. Purely local, unprivileged, no display or profiling access needed; only affects hosts with discrete Intel (lmem-capable) GPUs shared serially between workloads.
What to do
Boot a kernel carrying the i915 CCS-state fix below. Interim: do not recycle a GPU between tenants without a full device reset/scrub cycle, and prefer whole-device-per-tenant scheduling on discrete Intel cards until patched.
References
Related entries
- Linux kernel (drivers/gpu/drm/i915/gt): The GPU migration copy path used plain ints for sizes that a tenant controlsCVE-2022-49963 · Linux kernel (drivers/gpu/drm/i915/gt)High
- Linux kernel (drivers/vfio): VFIO core advertised migration ioctls for devices whose driver never actually initialisedCVE-2022-50117 · Linux kernel (drivers/vfio)Medium
- Linux kernel (net/xfrm): Transport-mode IPsec packets were reinjected in the same execution context instead of beingCVE-2022-50445 · Linux kernel (net/xfrm)Medium
- Xen on AMD - debug extensions (DBEXT) exposure to guests: AMD CPUs since roughly 2014 carry extensions to x86 debuggingCVE-2023-34327 · Xen on AMD - debug extensions (DBEXT) exposure to guestsMedium
- Xen on AMD - debug extensions (DBEXT) exposure to guests: Companion to the other XSA-444 debug-extension issue on AMD.CVE-2023-34328 · Xen on AMD - debug extensions (DBEXT) exposure to guestsMedium
- Arm Mali GPU kernel driver: Use-after-free via improper GPU memory processingCVE-2023-4211 · Arm Mali GPU kernel driverMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.