CyberRota Analysis
AI-GeneratedA vulnerability exists in kernel software running within a Host VM, allowing a malicious driver to exploit a time-of-check to time-of-use (TOCTOU) bug. This flaw enables the driver to issue improper commands to the GPU firmware, potentially leading to unauthorized memory writes outside the host kernel's permitted range. Organizations utilizing virtualized environments with GPU resources should prioritize addressing this high-severity issue to mitigate risks of memory corruption and potential system compromise.
Original NVD Description
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.