CVE-2022-49359: drm/panfrost: Job should reference MMU not file_priv
drm/panfrost: Job should reference MMU not filepriv
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify the panfrost job structure so it no longer keeps a reference to panfrost_priv (file_priv) and instead stores a direct reference to the MMU structure that corresponds to panfrost_priv, addressing the use-after-free (drm/panfrost: Job should reference MMU not file_priv).
Linux kernel (panfrost DRM driver) job structure reference (drm/panfrost: Job should reference MMU not file_priv) = Update job structure to drop reference to panfrost_priv and add a direct reference to the MMU structure
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49359?
CVE-2022-49359 has a medium severity rating due to potential privileges escalation risks within the Linux kernel.
Which versions of the Linux kernel are affected by CVE-2022-49359?
CVE-2022-49359 affects Linux kernel versions from 5.10.67 to 5.11, 5.13.19 to 5.14, 5.14.6 to 5.17.15, 5.18 to 5.18.4, and 5.19-rc1.
How do I fix CVE-2022-49359?
To fix CVE-2022-49359, update the Linux kernel to a patched version that addresses the vulnerability.
What type of vulnerability is CVE-2022-49359?
CVE-2022-49359 is categorized as a privileges escalation vulnerability affecting the job structure in the Linux kernel.
Can CVE-2022-49359 be exploited remotely?
CVE-2022-49359 is not classified as a remote code execution vulnerability, but it could potentially be exploited by local users to escalate privileges.