CVE-2024-39486: drm/drm_file: Fix pid refcounting race
drm/drmfile: Fix pid refcounting race
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (drm/drm_file)to a version that resolves this vulnerability.Patch CVE-2024-39486 - Compensating control
If applicable, note the issue is reported to occur only with CONFIG_PREEMPT_RCU=y; consider temporarily disabling CONFIG_PREEMPT_RCU=y or using an environment configuration that does not set it, until the fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39486?
CVE-2024-39486 has been classified with a severity level that suggests a potential risk to Linux kernel stability.
How do I fix CVE-2024-39486?
To fix CVE-2024-39486, update to the patched versions of the Linux kernel, specifically 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
Which versions of the Linux kernel are affected by CVE-2024-39486?
CVE-2024-39486 affects various versions of the Linux kernel from 6.6.9 to 6.6.37, and several 6.10 release candidates.
What kind of vulnerability is CVE-2024-39486?
CVE-2024-39486 is a race condition vulnerability related to pid refcounting within the Linux kernel DRM subsystem.
Is there a workaround for CVE-2024-39486?
There is no known workaround for CVE-2024-39486; patching the kernel is the recommended solution.