CVE-2024-47896: GPU DDK - rgxfw_hwr_log_info OOB write via psHWRInfoBuf->ui32WriteIndex
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47896?
CVE-2024-47896 has a high severity rating due to the potential for Guest VM exploitation of shared memory with GPU firmware.
How do I fix CVE-2024-47896?
To fix CVE-2024-47896, ensure you update the affected Android kernel to the latest security patch provided by your vendor.
What are the potential impacts of CVE-2024-47896?
The potential impacts of CVE-2024-47896 include data leakage or corruption by allowing Guest VMs to write outside of their allocated GPU memory.
Who is affected by CVE-2024-47896?
CVE-2024-47896 affects users running the Google Android operating system on devices that support virtualization.
Is CVE-2024-47896 being actively exploited?
As of now, there is no known active exploitation of CVE-2024-47896, but it poses a significant risk if left unaddressed.