Database/Firmware, BMC & network fabric
Linux i915 GPU kernel driver (HuC firmware load): The HuC delayed-loading fence is not released when probe fails early
Impact
The HuC delayed-loading fence is not released when probe fails early, leaving the driver in a broken state. Matters on nodes where the HuC firmware blob is missing or mismatched, which is a common outcome of an incomplete linux-firmware package in a slim container host image.
Who can reach it
Triggered on driver probe - so on node boot, not by a tenant.
What to do
Kernel update plus reboot. Also confirm the linux-firmware package on the node actually contains the matching GuC/HuC blobs for the installed silicon; a missing blob is what exposes this path in the first place.
References
Related entries
- ASPEED LPC snoop driver (drivers/soc/aspeed/aspeed-lpc-snoop.c): Under memory pressure an allocation in the LPC snoopCVE-2025-38145 · ASPEED LPC snoop driver (drivers/soc/aspeed/aspeed-lpc-snoop.c)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration self-deadlocks under memory pressure. AnCVE-2025-38373 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- Linux kernel (drivers/infiniband/hw/mlx5): An event subscription is published to the lookup table before its list headCVE-2025-38387 · Linux kernel (drivers/infiniband/hw/mlx5)Medium
- ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tearsCVE-2025-38487 · ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c)Medium
- Linux crypto/ccp - SEV platform shutdown error handling: The ccp driver's SEV/SNP platform shutdown path couldCVE-2025-39936 · Linux crypto/ccp - SEV platform shutdown error handlingMedium
- Linux kernel RDMA core address resolution (RDMA_NL_LS_OP_IP_RESOLVE netlink handler): The netlink handler forCVE-2025-71096 · Linux kernel RDMA core address resolution (RDMA_NL_LS_OP_IP_RESOLVE netlink handler)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.