Linux amdgpu: PSP firmware image copied into the 1 MiB private buffer without a size check
Impact
The amdgpu PSP path copied firmware images into the fixed 1 MiB fw_pri_buf with open-coded memset/memcpy and no validation of the image size, so an oversized or zero-length image overflowed or corrupted kernel memory adjacent to the private buffer. The fix makes psp_copy_fw return -ENODEV when the device is gone and -EINVAL when the size is zero or above 1 MiB. On an AMD Instinct node this is in the firmware-load path the driver runs at probe and on reset, so the practical consequence is kernel memory corruption or a failed GPU bring-up rather than a tenant-reachable escalation; the record gives no CVSS score and no evidence that an unprivileged tenant controls the image.
Who can reach it
Local, and effectively privileged: reaching the path requires control over the firmware image amdgpu loads or a device/driver state that drives psp_copy_fw with a bad size. No remote or tenant-pod vector is described in the record.
What to do
Take the stable kernel containing the psp_copy_fw validation on your amdgpu branch (three stable commits are listed) and reboot the node; the driver cannot be reloaded on a GPU node while workloads hold the devices, so this is a drain-and-reboot per node. No vendor advisory or standalone fixed version is given beyond the kernel git commits.
References
Related entries
- Linux amdkfd: caller-supplied doorbell id is not bounds checked in allocate_doorbellCVE-2026-97495 · Linux kernel drm/amdkfd (allocate_doorbell, caller-supplied doorbell id)Unscored
- Linux amdgpu userq: MQD and firmware buffer objects can be evicted, hanging the GPU nodeCVE-2026-97498 · Linux kernel drm/amdgpu user queues (MQD and firmware BO eviction)Unscored
- Linux drm/xe: NULL dereference when freeing a devcoredump snapshot that was never populatedCVE-2026-97519 · Linux kernel drm/xe (devcoredump snapshot cleanup)Unscored
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-001-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-003-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.