habanalabs kernel driver (gaudi_memset_device_memory): Use-after-free in the Gaudi device-memory memset path
Impact
Use-after-free in the Gaudi device-memory memset path: the command buffer is released on the error path and then dereferenced again. Gives a local accelerator user a kernel UAF - crash at minimum, and the usual UAF privilege-escalation potential with enough heap grooming.
Who can reach it
Local user holding the habanalabs device node, reached by driving the memset ioctl down an error path.
What to do
Fix ships in the Linux kernel. Update the kernel and reboot the node - in practice this is a drain plus reboot because the accelerator driver cannot be unloaded while jobs hold device file descriptors. No BIOS or firmware update needed.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.