CVE-2024-26943: nouveau/dmem: handle kcalloc() allocation failure
In the Linux kernel, the following vulnerability has been resolved:
nouveau/dmem: handle kcalloc() allocation failure
The kcalloc() in nouveaudmemevictchunk() will return null if the physical memory has run out. As a result, if we dereference srcpfns, dstpfns or dmaaddrs, the null pointer dereference bugs will happen.
Moreover, the GPU is going away. If the kcalloc() fails, we could not evict all pages mapping a chunk. So this patch adds a GFPNOFAIL flag in kcalloc().
Finally, as there is no need to have physically contiguous memory, this patch switches kcalloc() to kvcalloc() in order to avoid failing allocations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26943?
CVE-2024-26943 is classified as a high severity vulnerability due to the potential for dereferencing null pointers leading to crashes or undefined behavior.
How do I fix CVE-2024-26943?
To fix CVE-2024-26943, update your Linux kernel to one of the patched versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, or 6.12.10-1.
What software is affected by CVE-2024-26943?
CVE-2024-26943 affects the Linux kernel versions prior to those mentioned in the fixed versions, notably in Debian packages.
What are the consequences of not addressing CVE-2024-26943?
If CVE-2024-26943 is not addressed, systems may experience stability issues or crashes due to null pointer dereferencing.
Is CVE-2024-26943 under active exploit?
As of the latest information, there are no confirmed active exploits for CVE-2024-26943, but it is recommended to apply patches to mitigate potential risks.