Bug 556692
| Summary: | kernel: drm/radeon: r6xx/r7xx possible security issue, system ram access | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Eugene Teo (Security Response) <eteo> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | arozansk, rkhan, talltaurus2002, tao |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-10-19 09:04:10 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 559577 | ||
| Bug Blocks: | |||
|
Description
Eugene Teo (Security Response)
2010-01-19 04:45:56 UTC
This does not affect Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG as these Linux kernels do not have support for this drm device driver. I am glad to see fedora keeping an eye out on this. The whole bring the GPU out of lockup thing is scaring me too. Because once it's able to bring it out of lockup then it's more open to attacks that aren't identifiable by a frozen computer. Number two on my this is scary and stupid list is onboard video designed to work with discrete gpu's or hybrid sli. What is horrible about this is they simply disable the vram and use the system ram. Why they didn't design this to force the discrete gpu to handle all the memory and to be plugged to the monitor using it's frame buffer instead of giving the frame buffer to the onboard GPU. That breaks hybrid power where you disable the onboard gpu entirely to save power, but the using a frame buffer in system ram ONLY and ALL THE TIME seems to want to be manipulated into being exploitable. My huge concerns. Intel wants to be able to bring GPU out of lockup. Intel wants to handle the frame buffer on all this. Intel is asserting rights to these busses and being strange and protective with cross licensing. Everyone else wants to include gpu in every system either on cpu or in a multi chip package. The onboard gpu's aren't capable because of strange ways they use the pci busses. When nearly the exact same chip is capable of 4.8 gtexel/s and 2.4 gpixels/s in discrete form but can only manage 800mega texels and 400 mega pixels in MCP form it's strange. If it's not benefiting the consumer who is it for? Protect GPU gart with machine guns if necessary. Give options on GPU lockup recovery. None of this stuff will be a concern on shader model 3.0 but 4.0 and 5.0 are extremely suspect. When cpu's lockup the systems crash. They should do the same thing when gpu's lock up. I'm not an expert on all this but I know enough to be concerned. Even law enforcement doesn't have the right to turn everyone's computers into a crashing flaking rape train. Stick around using the GPU as an attack vector should be coming any time now. It'll get more sophisticated as OpenCL and Direct Compute become more common. |