GPU VulnDB

Database/NVIDIA / GPU stack

Linux kernel amdgpu: unclamped write position in the vBIOS update sysfs attribute overflows the buffer

UnscoredCVE-2026-97425NVIDIA / GPU stackcurated

Impact

The amdgpu vBIOS update path exposed a sysfs binary attribute whose declared size did not bound the write position, so the VFS layer did not block out-of-bounds writes and a write past the end of the buffer was possible. The fix sets the bin attribute size to the maximum buffer size so VFS rejects the overflow. Reaching this attribute requires write access to amdgpu sysfs, which on a normal node means root on the host, so the realistic exposure is a privileged-process memory-corruption primitive rather than a tenant escape - but it sits on the firmware update path of the accelerator, where corruption affects a device that is expensive to recover.

Who can reach it

Local root (or a process holding write access to the amdgpu device sysfs tree) on the GPU host. Not reachable from an unprivileged container that merely has a GPU assigned, and not reachable over the network.

What to do

Take the stable backports linked in the record and reboot each AMD GPU node on a patched kernel after draining it. No vendor advisory with a product-level fixed version accompanies this record; the kernel commits are the authoritative fix. Interim mitigation is simply not granting host-sysfs write access to anything that does not need it.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.