Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/nouveau): Calling the legacy pushbuf submission ioctl on a client that has VM_BIND
Impact
Calling the legacy pushbuf submission ioctl on a client that has VM_BIND enabled returns an error with the client mutex still held. The tenant's next ioctl and its file close both deadlock, leaving an unkillable task that pins GPU contexts and memory which never return to the pool for other tenants.
Who can reach it
Tenant container holding /dev/dri/renderD* on nouveau: enable VM_BIND on the client, then call DRM_IOCTL_NOUVEAU_GEM_PUSHBUF. One ioctl, deterministic, unprivileged - no race window to win.
What to do
Update to a kernel carrying the fix (stable commits below; no fixed_in published). Interim: none - both ioctls are on the normal submission interface; drain and reboot nodes with stuck nouveau clients.
References
Related entries
- Linux kernel (drivers/gpu/drm/nouveau): Importing a dma-buf whose backing buffer object fails to initialize leaves theCVE-2022-50454 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): Nouveau's VM_BIND remap path miscalculates the address and range of the unmapCVE-2024-36018 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): A buffer object imported over PRIME leaves a dangling pointer behind, and theCVE-2025-37765 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): When the device-to-host copy behind a page fault silently fails, the faultCVE-2024-50096 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistCVE-2024-35841 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Tls_init published the new sk_prot before the TLS context was fully initialized, so aCVE-2024-36489 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.