GPU VulnDB

Database/Firmware, BMC & network fabric

Intel processor graphics blitter command streamer: MULTI-TENANT ISOLATION: The graphics blitter accepted commands

CVE-2019-0155Firmware, BMC & network fabriciGPU Leakcurated

Impact

MULTI-TENANT ISOLATION: The graphics blitter accepted commands that could reference memory outside the submitting context, letting a local user with GPU access read or write memory belonging to another context. This is the archetype of the GPU isolation failure operators care about: one tenant's GPU commands reaching another tenant's GPU memory. Mitigated by kernel command parsing, which costs measurable submission throughput.

Who can reach it

Any local user or container able to submit GPU work through the DRM interface.

What to do

Take the kernel fix (which re-enables blitter command parsing) plus the Intel graphics firmware/driver update, then reboot. Expect a performance regression on blitter-heavy workloads - that is the mitigation working, not a bug. Kernel + graphics driver, no BIOS.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.