Database/Control plane, storage & DevOps
Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the Instruction
Impact
On AMD Zen systems, the Instruction Fetch unit does not report the address of a poisoned (uncorrectable-error) instruction fetch, and the kernel was not saving the CS register either - so when memory corruption hits an instruction fetch, you lose the information needed to attribute it. On a GPU training fleet where uncorrectable memory errors are a routine operational event, losing attribution means you cannot tell which tenant's job hit the bad memory or which DIMM to replace.
Who can reach it
Not attacker-driven. This is an observability failure on the machine-check path.
What to do
Fixed in the Linux kernel. Distro kernel update plus reboot. Worth taking on any fleet where you do RAS-driven node retirement - without it your machine-check records are missing the field you need to act on.
References
Related entries
- Linux i915 GVT-g mediated GPU virtualisation: Unsafe cleanup of per-vGPU debugfs state when a mediated vGPU isCVE-2023-53625 · Linux i915 GVT-g mediated GPU virtualisationMedium
- Citrix NetScaler ADC/Gateway: Code injection on the management interfaceCVE-2023-6548 · Citrix NetScaler ADC/GatewayMedium
- Linux nfsd (NFS server): Broken RELEASE_LOCKOWNER handling in nfsd causing state corruptionCVE-2024-26629 · Linux nfsd (NFS server)Medium
- Intel Neural Compressor: Input-validation failure reachable by an authenticated user, ending in privilege escalationCVE-2024-36284 · Intel Neural CompressorMedium
- AMD Graphics Driver - integer overflow bypassing size checks: An integer overflow in the AMD graphics driver letsCVE-2024-36316 · AMD Graphics Driver - integer overflow bypassing size checksMedium
- Linux cpufreq/amd-pstate - memory leak on CPU EPP exit: The amd-pstate driver leaks its per-CPU allocation when a CPU'sCVE-2024-40997 · Linux cpufreq/amd-pstate - memory leak on CPU EPP exitMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.