Linux kernel i915: memory leak in the perf config list query on allocation failure
Impact
The i915 DRM_IOCTL_I915_QUERY handler for the performance config list leaked the oa_config_ids buffer when krealloc() failed, returning without freeing the previous allocation. The practical effect is kernel memory lost per failed query, reachable by a local process holding a DRM fd on an Intel graphics device; it is not a corruption or privilege-escalation path. Relevance to a GPU fleet is limited and configuration-specific: it applies to nodes where i915 is bound - Intel integrated display on the host, or Intel accelerators driven by i915 rather than xe - and on headless servers with no i915 device bound it is unreachable. Where it does apply and a tenant can open /dev/dri, repeated failed queries are a slow memory-pressure nuisance rather than a tenancy break.
Who can reach it
Local user able to open an i915 DRM device node (/dev/dri/*) and issue the query ioctl. No remote path. Requires the allocation to fail, i.e. the system already under memory pressure.
What to do
Pick up the stable kernel commit that frees oa_config_ids on the krealloc() failure path (cherry-picked from 9977e9d84f46), which means a node drain and reboot. Low urgency relative to that cost; an operator can reasonably fold it into the next scheduled kernel roll. Restricting /dev/dri access for untrusted tenants removes the reachable path in the meantime. No fixed distro version is named in the record.
References
Related entries
- Linux kernel drm_exec: empty object array leaves contention unresolved and spins foreverCVE-2026-97900 · Linux kernel drm_exec (drm_exec_prepare_array with num_objects == 0)Unscored
- Linux kernel accel/qaic: unbounded response message walk in resp_worker() reads past the slab allocationCVE-2026-98155 · Linux kernel accel/qaic (Qualcomm Cloud AI 100 accelerator driver)Unscored
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-001-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-003-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA): GPUs apply data-dependent losslessNCVD-2023-003-integrated-gpu-graphics-data-com · Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.