GPU VulnDB

Database/NVIDIA / GPU stack

Linux kernel i915: memory leak in the perf config list query on allocation failure

UnscoredCVE-2026-97899NVIDIA / GPU stackcurated

Impact

The i915 DRM_IOCTL_I915_QUERY handler for the performance config list leaked the oa_config_ids buffer when krealloc() failed, returning without freeing the previous allocation. The practical effect is kernel memory lost per failed query, reachable by a local process holding a DRM fd on an Intel graphics device; it is not a corruption or privilege-escalation path. Relevance to a GPU fleet is limited and configuration-specific: it applies to nodes where i915 is bound - Intel integrated display on the host, or Intel accelerators driven by i915 rather than xe - and on headless servers with no i915 device bound it is unreachable. Where it does apply and a tenant can open /dev/dri, repeated failed queries are a slow memory-pressure nuisance rather than a tenancy break.

Who can reach it

Local user able to open an i915 DRM device node (/dev/dri/*) and issue the query ioctl. No remote path. Requires the allocation to fail, i.e. the system already under memory pressure.

What to do

Pick up the stable kernel commit that frees oa_config_ids on the krealloc() failure path (cherry-picked from 9977e9d84f46), which means a node drain and reboot. Low urgency relative to that cost; an operator can reasonably fold it into the next scheduled kernel roll. Restricting /dev/dri access for untrusted tenants removes the reachable path in the meantime. No fixed distro version is named in the record.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.