GPU VulnDB

Database/NVIDIA / GPU stack

Linux amdgpu: PSP firmware image copied into the 1 MiB private buffer without a size check

UnscoredCVE-2026-97494NVIDIA / GPU stackcurated

Impact

The amdgpu PSP path copied firmware images into the fixed 1 MiB fw_pri_buf with open-coded memset/memcpy and no validation of the image size, so an oversized or zero-length image overflowed or corrupted kernel memory adjacent to the private buffer. The fix makes psp_copy_fw return -ENODEV when the device is gone and -EINVAL when the size is zero or above 1 MiB. On an AMD Instinct node this is in the firmware-load path the driver runs at probe and on reset, so the practical consequence is kernel memory corruption or a failed GPU bring-up rather than a tenant-reachable escalation; the record gives no CVSS score and no evidence that an unprivileged tenant controls the image.

Who can reach it

Local, and effectively privileged: reaching the path requires control over the firmware image amdgpu loads or a device/driver state that drives psp_copy_fw with a bad size. No remote or tenant-pod vector is described in the record.

What to do

Take the stable kernel containing the psp_copy_fw validation on your amdgpu branch (three stable commits are listed) and reboot the node; the driver cannot be reloaded on a GPU node while workloads hold the devices, so this is a drain-and-reboot per node. No vendor advisory or standalone fixed version is given beyond the kernel git commits.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.