Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/gsp): The GSP message-queue read pointer is advanced by the wrong
Impact
The GSP message-queue read pointer is advanced by the wrong amount, so the driver parses message body bytes as a header, underflows the copy-length computation to a ~0xffffffff value and then dereferences a NULL message pointer. Oversized copy plus kernel panic - the node goes down for every tenant sharing it.
Who can reach it
Same GSP RPC path as CVE-2024-58018: two-page GSP event messages generated during normal tenant-driven GPU activity on a nouveau/GSP-firmware NVIDIA GPU. A tenant holding /dev/dri/renderD* supplies the workload that produces those messages; no capabilities required. Not applicable when the NVIDIA vendor module is in use.
What to do
Update to a kernel carrying the fix (stable commits below; no fixed_in published). Interim: run the vendor kernel module rather than nouveau on shared GSP-class GPUs.
References
Related entries
- Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/gsp): The driver miscalculates free space in the GSP firmware commandCVE-2024-58018 · Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/gsp)Medium
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amdgpu): An out-of-bounds access in the amdgpu powerCVE-2025-21780 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A use-after-free in the amdgpu display core (DC/DM)CVE-2025-21968 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2025-21985 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- GPU Display Driver: Local privesc (insufficient access control)CVE-2025-23244 · GPU Display DriverHigh
- Megatron-LM: Arbitrary code execution in the training jobCVE-2025-23264 · Megatron-LMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.