Executive brief
A vulnerability in the Linux kernel's HiSilicon graphics driver could allow a local user to cause a system crash or potentially gain unauthorized access. The issue occurs when the system attempts to manage hardware interrupts using temporary memory that is cleared too early. This can lead to unpredictable system behavior or a complete service outage on affected hardware.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c within the hibmc_msi_init function. The driver was passing a pointer to a local stack-allocated string ('name') to devm_request_threaded_irq() and devm_request_irq(). Because these functions expect the name pointer to remain valid for the lifetime of the IRQ registration, the stack frame's destruction leads to a UAF condition. A local attacker could potentially exploit this to cause a kernel panic (DoS) or achieve privilege escalation. The fix involves using a global static array for IRQ names to ensure the memory remains valid. Patches are available in kernel versions 6.16.4 and 6.17.
Affected products
- Linux Linux Kernel 6.16 to 6.16.4
Timeline
- 2025-08-13: disclosed: Initial patch submitted by Huawei developers
- 2025-08-28: patched: Patch committed to stable tree
- 2025-09-11: advisory: CVE published by kernel.org