Database/Kernel, userspace & hypervisor
Linux perf/x86/amd/brs - kernel address leakage through Branch Sampling: A user-only branch stack collected via AMD
Impact
A user-only branch stack collected via AMD Branch Sampling can contain branches that originated in the kernel, so unprivileged profiling leaks kernel addresses. That is a KASLR break handed to any tenant allowed to profile their own code - and on AI clusters, letting tenants profile their own GPU and CPU kernels is a feature people ask for. Combine it with any of the amdgpu memory-safety bugs in this database and you have a reliable local privilege escalation.
Who can reach it
Local, from a process permitted to use perf branch sampling. How reachable this is depends entirely on your perf_event_paranoid setting - if you relaxed it so tenants can profile, you granted this.
What to do
Fixed in the Linux kernel by filtering kernel branches out of user-only branch stacks. Distro kernel update plus reboot; no firmware step. In the meantime, review perf_event_paranoid on GPU nodes: the value that makes tenant profiling work is the same value that exposes this.
References
Related entries
- Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sourcesCVE-2026-72402 · Linux kernel BPF verifier (ldimm64 pseudo-pointer masking in verifier logs)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-74353 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingCVE-2026-74448 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel vhost: stale vring metadata cache lets a reconfigured vring access memory outside its IOTLB mappingCVE-2026-74580 · Linux kernel vhost (vring metadata IOTLB cache)Unscored
- Linux kernel BPF sockmap: use-after-free on the cached redirect socket in the send verdict pathCVE-2026-74589 · Linux kernel BPF sockmap (tcp_bpf_send_verdict sk_redir refcount)Unscored
- Linux kernel mm/filemap: page cache folio can be stored at the wrong index after an allocation retryCVE-2026-74591 · Linux kernel mm/filemap (__filemap_add_folio index restore on retry)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.