Database/Control plane, storage & DevOps
Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HID
Impact
A use-after-free in the AMD Sensor Fusion Hub HID driver: driver_data is freed in the wrong order relative to hid_destroy_device(), so callbacks touch memory that is already gone. Kernel UAF is a privilege-escalation primitive. AMD SFH is a client-platform driver and unlikely to be loaded on an Instinct server - but it is compiled into stock distro kernels, and a driver that is present but unneeded is attack surface you are carrying for nothing.
Who can reach it
Local, on hosts where the amd_sfh driver is loaded.
What to do
Fixed in the Linux kernel; take the distro update and reboot. Better: blacklist amd_sfh on server images. Auditing your GPU nodes for client-platform drivers that autoload and are never used is a cheap one-off that shrinks the kernel attack surface permanently.
References
Related entries
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itCVE-2026-11332 · ansible-core (ansible-galaxy role install, git argument injection via meta/requirements.yml)High
- ansible-core: git argument injection in ansible-galaxy collection install yields command executionCVE-2026-16493 · ansible-core (ansible-galaxy collection install, git source URL handling)High
- MUNGE (munged credential daemon): This is the root of trust under Slurm. A crafted message with an oversizedCVE-2026-25506 · MUNGE (munged credential daemon)High
- VMware Avi Load Balancer: local user can escalate to root on the applianceCVE-2026-47868 · VMware Avi Load Balancer (Controller and Service Engine appliance)High
- Linuxfabrik monitoring plugins: pipe injection in shell_exec escalates a check account to rootCVE-2026-55426 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.shell.shell_exec)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.