Database/Kernel, userspace & hypervisor
Linux i915 GPU kernel driver (GEM tiling): A double-free reachable by racing I915_GEM_SET_TILING from multiple threads.
Impact
A double-free reachable by racing I915_GEM_SET_TILING from multiple threads. Double-free in the kernel slab allocator is the most directly weaponisable class here - it gives an attacker with GPU access a well-understood route to arbitrary kernel write and therefore to the host and every co-tenant on the node.
Who can reach it
Any local user or container with a DRM render node - i.e. any tenant that was scheduled a GPU. No privileged capability needed.
What to do
Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2023-53009 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux i915 GPU kernel driver (active barrier tracking): Non-idle barriers were misused as fence trackers, corruptingCVE-2023-53087 · Linux i915 GPU kernel driver (active barrier tracking)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedCVE-2023-53090 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans aCVE-2023-53236 · Linux kernel (drivers/iommu/iommufd)High
- Linux i915 GPU kernel driver (display page table objects): The buffer object backing a display page tableCVE-2023-53378 · Linux i915 GPU kernel driver (display page table objects)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2023-53552 · Linux i915 GPU kernel driverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.