Database/Kernel, userspace & hypervisor
Intel i915 graphics driver for Linux (kernel < 6.2.10): A memory-buffer bounds failure in the i915 kernel driver that
Impact
A memory-buffer bounds failure in the i915 kernel driver that an authenticated local user can drive into privilege escalation. i915 is the driver behind Intel integrated and Data Center GPU nodes, and it is reachable from inside any container that has been granted /dev/dri - so this is a container-to-host kernel escape on Intel-GPU nodes.
Who can reach it
Any local user or container with access to the DRM render node. No special hardware access beyond having been scheduled a GPU.
What to do
Update to a Linux kernel with the fix (6.2.10 or later upstream, or your distro's backport) and reboot. i915 cannot be reloaded under running GPU workloads, so drain the node. No BIOS, firmware or microcode component.
References
Related entries
- CephFS/RBD kernel client (libceph messenger v2): A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosenCVE-2023-44466 · CephFS/RBD kernel client (libceph messenger v2)High
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesCVE-2023-53630 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listCVE-2023-54043 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.