GPU VulnDB

Database/NVIDIA / GPU stack

Linux kernel amdgpu powerplay: pp_table sysfs write memcpys up to PAGE_SIZE into a smaller heap buffer

UnscoredCVE-2026-97427NVIDIA / GPU stackcurated

Impact

The powerplay table is held in a buffer allocated once with kmemdup() at soft_pp_table_size, but the sysfs store handler memcpy'd the caller-supplied byte count - up to PAGE_SIZE - with no upper bound, giving a straightforward heap overflow with attacker-chosen contents. This is a write primitive in the AMD GPU power-management path, usable for kernel memory corruption and therefore for escalation or a host crash. Access is gated on write permission to the amdgpu powerplay sysfs node, normally root on the host, so the operator question is containment of privileged tooling (fleet power-capping and tuning agents commonly write here) rather than tenant isolation. The fix rejects writes larger than soft_pp_table_size.

Who can reach it

Local process with write access to the amdgpu pp_table sysfs attribute - host root in a default configuration. Not exposed to GPU tenants through /dev/kfd or /dev/dri alone, and not network reachable.

What to do

Apply the stable kernel backports listed in the record (five branches carry the fix) and reboot each affected AMD GPU node after draining it. The record carries no vendor advisory or distro fixed version, so track your distro's kernel update rather than a stated version. Meanwhile, audit which daemons and sidecars are allowed to write amdgpu powerplay sysfs.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.