CVE-2024-41092: drm/i915/gt: Fix potential UAF by revoke of fence registers
drm/i915/gt: Fix potential UAF by revoke of fence registers
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.221 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.162 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.97 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.37 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9.8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.10 - Upgrade
Upgrade
Linux kernel drm/i915/gtto a version that resolves this vulnerability.Patch drm/i915/gt: Fix potential UAF by revoke of fence registers - Upgrade
Upgrade
Linux kernel drm/i915/gtto a version that resolves this vulnerability.Patch drm/i915/gt: Make fence revocation unequivocal - Upgrade
Upgrade
Linux kernel drm/i915/gtto a version that resolves this vulnerability.Patch drm/i915/gt: Only wait for GPU activity before unbinding a GGTT fence - Upgrade
Upgrade
Linux kernel drm/i915/gtto a version that resolves this vulnerability.Patch Fix it by waiting for idleness of vma->fence->active in i915_vma_revoke_fence()
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41092?
CVE-2024-41092 has a high severity due to the potential for a use-after-free vulnerability in the Linux kernel.
How do I fix CVE-2024-41092?
To fix CVE-2024-41092, update to the patched versions of the Linux kernel such as 5.10.221, 5.15.162, 6.1.97, or newer.
What affected systems are vulnerable to CVE-2024-41092?
Systems running vulnerable versions of the Linux kernel before 5.10.221, 5.15.162, or 6.1.97 are at risk for CVE-2024-41092.
What type of vulnerability is CVE-2024-41092?
CVE-2024-41092 is categorized as a use-after-free vulnerability affecting the drm/i915 component of the Linux kernel.
What impact can CVE-2024-41092 have on my system?
If exploited, CVE-2024-41092 can lead to unauthorized access or privilege escalation, potentially compromising system security.