Linux amdgpu: unbounded FRU PIA TLV walk reads out of bounds on malformed EEPROM data
Impact
The amdgpu driver's FRU (board inventory) parser walked TLV records without bounding reads against the actual EEPROM data length, so truncated or malformed FRU content causes out-of-bounds reads in kernel context. On an AMD Instinct node this parsing runs during GPU probe, so the failure mode is kernel memory disclosure into board-info surfaces or a driver/boot-time crash on a node that was otherwise healthy. Reaching it requires influence over the FRU EEPROM content rather than tenant workload input, which keeps the practical exposure low on a fleet with intact hardware, but a re-flashed or damaged board can take the node down on every boot. Fixed by replacing the open-coded walk with bounded fru_pia_advance()/fru_pia_copy_field() helpers.
Who can reach it
Local and hardware-adjacent: requires malformed or truncated FRU EEPROM data on the GPU board, not tenant-reachable input. No remote or unauthenticated path is described in the record.
What to do
Take the stable kernel update carrying the bounded FRU parsing helpers (three stable commits referenced). The amdgpu module cannot be reloaded under live GPU workloads in practice, so this is a drain-and-reboot per GPU node, scheduled with normal kernel maintenance rather than urgently given the limited reachability.
References
Related entries
- DGX H100 BMC (IPMI): Credential exposureCVE-2023-25531 · DGX H100 BMC (IPMI)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- Container Toolkit / GPU Operator: Container escape to host root (insufficient input validation)CVE-2024-0135 · Container Toolkit / GPU OperatorHigh
- Container Toolkit / GPU Operator: Container escape to host (insufficient input validation)CVE-2024-0136 · Container Toolkit / GPU OperatorHigh
- IGX Orin bootloader: Improper access control in bootloaderCVE-2024-0148 · IGX Orin bootloaderHigh
- NeMo Framework: RCE via insecure deserializationCVE-2025-23249 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.