CVE-2024-26922: drm/amdgpu: validate the parameters of bo mapping operations more clearly
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate the parameters of bo mapping operations more clearly
The Linux kernel CVE team has assigned CVE-2024-26922 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024042317-CVE-2024-26922-896d@gregkh/T
Other sources
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate the parameters of bo mapping operations more clearly
Verify the parameters of amdgpuvmbo(map/replacemap/clearingmappings) in one common place.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2024-26922
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26922?
CVE-2024-26922 has been classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-26922?
To mitigate CVE-2024-26922, upgrade your Linux kernel to versions higher than 6.9 or the specific patched version on Debian.
Which Linux kernel versions are affected by CVE-2024-26922?
The affected Linux kernel versions include 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.9-1, 6.12.10-1 for Debian, and kernel versions below 6.9 for Red Hat.
What are the consequences of CVE-2024-26922?
Exploitation of CVE-2024-26922 may lead to unauthorized access to system memory through improper handling of graphic memory mapping.
Who is impacted by CVE-2024-26922?
Any users or organizations using vulnerable versions of the Linux kernel, particularly those relying on graphic processing features, are impacted by CVE-2024-26922.