Database/Kernel, userspace & hypervisor
Linux i915 GPU kernel driver (display page table objects): The buffer object backing a display page table
Impact
The buffer object backing a display page table was not treated as a framebuffer, letting it be moved or reused while the display engine still pointed at it. Practical outcome on a headless GPU node is a driver crash rather than a tenant boundary break, but on nodes that do run display output it can surface other memory on screen.
Who can reach it
Any local user or container with a DRM render node - i.e. any tenant that was scheduled a GPU. No privileged capability needed.
What to do
Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.
References
Related entries
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2023-53552 · Linux i915 GPU kernel driverHigh
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andCVE-2023-53781 · Linux kernel (net/smc)High
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theCVE-2023-53795 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverCVE-2023-53816 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2023-54202 · Linux i915 GPU kernel driverHigh
- Linux kernel (netfilter pipapo): Inactive elements mishandled in nft_pipapo_walk - use-after-free, local rootCVE-2023-6817 · Linux kernel (netfilter pipapo)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.