First published: Thu Jul 18 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We remap the HDP flush registers into this space to allow userspace (CPU or GPU) to flush the HDP when it updates VRAM. However, on systems with >4K pages, we end up exposing PAGE_SIZE of MMIO space.
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=5.3<5.4.283 | |
Linux Kernel | >=5.5<5.10.225 | |
Linux Kernel | >=5.11<5.15.166 | |
Linux Kernel | >=5.16<6.1.91 | |
Linux Kernel | >=6.7<6.8.10 | |
Linux Kernel | =6.9-rc1 | |
Linux Kernel | =6.9-rc2 | |
Linux Kernel | =6.9-rc3 | |
Linux Kernel | =6.9-rc4 | |
Linux Kernel | =6.9-rc5 | |
Linux Kernel | =6.9-rc6 | |
Linux Kernel | =6.9-rc7 | |
debian/linux | <=5.10.223-1 | 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41011 is classified as having a high severity due to the potential for memory corruption in the Linux kernel.
To mitigate CVE-2024-41011, update your Linux kernel to a version higher than 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
CVE-2024-41011 affects Linux kernel versions from 5.3 up to but not including 5.10.226-1 and similar versions.
Yes, CVE-2024-41011 has been identified in the Debian distribution of the Linux kernel.
CVE-2024-41011 may lead to exploitation through memory corruption that could allow an attacker to execute arbitrary code.