Linux kernel amdgpu: unclamped write position in the vBIOS update sysfs attribute overflows the buffer
Impact
The amdgpu vBIOS update path exposed a sysfs binary attribute whose declared size did not bound the write position, so the VFS layer did not block out-of-bounds writes and a write past the end of the buffer was possible. The fix sets the bin attribute size to the maximum buffer size so VFS rejects the overflow. Reaching this attribute requires write access to amdgpu sysfs, which on a normal node means root on the host, so the realistic exposure is a privileged-process memory-corruption primitive rather than a tenant escape - but it sits on the firmware update path of the accelerator, where corruption affects a device that is expensive to recover.
Who can reach it
Local root (or a process holding write access to the amdgpu device sysfs tree) on the GPU host. Not reachable from an unprivileged container that merely has a GPU assigned, and not reachable over the network.
What to do
Take the stable backports linked in the record and reboot each AMD GPU node on a patched kernel after draining it. No vendor advisory with a product-level fixed version accompanies this record; the kernel commits are the authoritative fix. Interim mitigation is simply not granting host-sysfs write access to anything that does not need it.
References
Related entries
- Linux kernel amdgpu powerplay: pp_table sysfs write memcpys up to PAGE_SIZE into a smaller heap bufferCVE-2026-97427 · Linux kernel amdgpu powerplay (pp_dpm_set_pp_table sysfs store)Unscored
- Linux kernel drm/amdgpu: unbounded VBIOS GPIO I2C entry count overruns adev->i2c_bus[]CVE-2026-97493 · Linux kernel amdgpu VBIOS GPIO I2C table parsing (drm/amdgpu)Unscored
- Linux amdgpu: PSP firmware image copied into the 1 MiB private buffer without a size checkCVE-2026-97494 · Linux kernel drm/amdgpu (PSP firmware private buffer, psp_copy_fw)Unscored
- Linux amdkfd: caller-supplied doorbell id is not bounds checked in allocate_doorbellCVE-2026-97495 · Linux kernel drm/amdkfd (allocate_doorbell, caller-supplied doorbell id)Unscored
- Linux amdgpu userq: MQD and firmware buffer objects can be evicted, hanging the GPU nodeCVE-2026-97498 · Linux kernel drm/amdgpu user queues (MQD and firmware BO eviction)Unscored
- Linux drm/xe: NULL dereference when freeing a devcoredump snapshot that was never populatedCVE-2026-97519 · Linux kernel drm/xe (devcoredump snapshot cleanup)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.