Linux drm/xe: NULL dereference when freeing a devcoredump snapshot that was never populated
Impact
In xe_devcoredump_snapshot_free() the snapshot's gt pointer can be NULL if cleanup runs without a prior capture, and xe_guc_capture_put_matched_nodes() was called on it unguarded; xe_devcoredump_free() likewise called cancel_work_sync() on work that is only queued once a coredump is captured. Either path is a kernel NULL dereference, so the effect is an oops on the node. On an Intel Data Center GPU host this is a crash-and-reboot, not a tenant escape: the trigger is the driver's own error-reporting teardown, which a tenant does not drive directly. The record gives no CVSS score, and it does not describe any way to reach the path on demand.
Who can reach it
Local and indirect: the path runs during xe devcoredump teardown, typically after a GPU error or on driver unload. No authenticated remote or tenant-facing vector is described.
What to do
Take a stable kernel with the IS_ERR_OR_NULL and coredump->captured guards (two stable commits listed) at your next kernel update and reboot the node. Low urgency for a headless fleet unless you are already chasing xe coredump oopses. No vendor advisory or fixed version is in the record.
References
Related entries
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-001-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-003-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA): GPUs apply data-dependent losslessNCVD-2023-003-integrated-gpu-graphics-data-com · Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA)Unscored
- NVIDIA Confidential Computing (H100/H200/B100/B200/GB200) - CC-DevTools operating mode: NVIDIA GPU confidentialNCVD-2023-004-nvidia-confidential-computing-h1 · NVIDIA Confidential Computing (H100/H200/B100/B200/GB200) - CC-DevTools operating modeUnscored
- Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA): GPUs apply data-dependent losslessNCVD-2023-005-integrated-gpu-graphics-data-com · Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.