Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/nouveau): When the device-to-host copy behind a page fault silently fails, the fault
Impact
When the device-to-host copy behind a page fault silently fails, the fault handler still hands the process a HIGH_USER page that was never written. The tenant reads whatever was previously in that page - residual data from other workloads on the node. This is the cross-tenant information-disclosure case, and the upstream fix calls it a security vulnerability in those words.
Who can reach it
Tenant holding /dev/dri/renderD* on nouveau using SVM/HMM device memory: fault a migrated page back to host RAM while the copy engine fails (a hung or erroring GPU, itself tenant-inducible). No capabilities required. nouveau device-memory (dmem) path only.
What to do
Update to a kernel carrying the fix (stable commits below; no fixed_in published). Interim: disable SVM/HMM device memory on nouveau nodes, or do not share nouveau GPUs across tenants.
References
Related entries
- Linux kernel (drivers/gpu/drm/nouveau): Calling the legacy pushbuf submission ioctl on a client that has VM_BINDCVE-2024-35786 · Linux kernel (drivers/gpu/drm/nouveau)Medium
- Linux kernel (drivers/gpu/drm/nouveau): Importing a dma-buf whose backing buffer object fails to initialize leaves theCVE-2022-50454 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): Nouveau's VM_BIND remap path miscalculates the address and range of the unmapCVE-2024-36018 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (drivers/gpu/drm/nouveau): A buffer object imported over PRIME leaves a dangling pointer behind, and theCVE-2025-37765 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (uvcvideo): Out-of-bounds write parsing UVC_VS_UNDEFINED frames - exploited in the wildCVE-2024-53104 · Linux kernel (uvcvideo)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (anCVE-2025-23241 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.