Executive brief
A memory safety flaw in the Linux kernel's Intel GPU virtualization (GVT) debugfs cleanup code can cause a system crash when a virtual GPU device is removed. The bug occurs because the code attempts to access a debug filesystem directory that has already been freed, leading to a kernel panic and denial of service. This impacts users running virtual GPU workloads on Intel integrated graphics.
Technical details
The vulnerability is a use-after-free condition in intel_gvt_debugfs_clean() where the function attempts to remove a debugfs entry without checking if the parent debugfs root directory is still valid. During device unbinding, the DRM minor's debugfs directory is removed first, but the GVT cleanup code later attempts to operate on the already-freed pointer, triggering a NULL pointer dereference in down_write(). The vulnerability affects the drm/i915/gvt module when GVT-capable devices are dynamically removed via unbinding. A fix involves adding a NULL check on the debugfs root before attempting recursive removal, preventing the kernel panic during device hot-removal or unbinding scenarios.
Affected products
- Linux Linux kernel 6.1.0-rc8 and earlier versions with drm/i915/gvt
Timeline
- 2023: disclosed: CVE-2023-54098 assigned
- 2023: patched: Fix merged into Linux kernel mainline