| Version | Supported |
|---|---|
| 0.0.x | ✅ Security fixes |
If you discover a security vulnerability, please report it responsibly. Do not open a public issue for security problems.
- GitHub Security Advisories: submit a private report.
- Bug Bounty: this project does not currently offer a public bug bounty program.
- A clear and concise description of the vulnerability.
- Steps to reproduce the issue.
- Any potential attack scenario or security impact.
- Suggested mitigations or fixes, if available.
This device plugin registers AMD GPUs to Kubernetes and applies HAMi soft vGPU
limits: memory through HIP_DEVICE_MEMORY_LIMIT_<i> and the libamvgpu.so
LD_AUDIT hook, plus a kernel dmem cgroup cap where the node supports it,
and compute through HSA_CU_MASK. These limits are for cooperative
multi-tenant sharing on a trusted cluster. The hook and the CU mask are not a
hard security boundary against a workload with enough privilege to bypass its
own hook, for example by unsetting the audit library, using a static binary,
or ptrace.
- A report that a workload can exceed its own quota, without affecting another tenant, is not a new vulnerability by itself.
- A report that lets a workload reach another tenant's data, device, or namespace it was not granted is in scope; please report it through the process above.
Response times may be affected by weekends, holidays, or time-zone differences. The maintainers aim to reply as soon as possible, ideally within 5 working days.
This project relies on third-party Go modules and container base images. We monitor them with Dependabot and apply security patches promptly.
Thank you for helping keep the project secure.