CVE-2024-49942: drm/xe: Prevent null pointer access in xe_migrate_copy
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Prevent null pointer access in xemigratecopy
xemigratecopy designed to copy content of TTM resources. When source resource is null, it will trigger a NULL pointer dereference in xemigratecopy. To avoid this situation, update lacks source flag to true for this case, the flag will trigger xemigrateclear rather than xemigratecopy.
Issue trace: <7> [317.089847] xe 0000:00:02.0: [drm:xemigratecopy [xe]] Pass 14, sizes: 4194304 & 4194304 <7> [317.089945] xe 0000:00:02.0: [drm:xemigratecopy [xe]] Pass 15, sizes: 4194304 & 4194304 <1> [317.128055] BUG: kernel NULL pointer dereference, address: 0000000000000010 <1> [317.128064] #PF: supervisor read access in kernel mode <1> [317.128066] #PF: errorcode(0x0000) - not-present page <6> [317.128069] PGD 0 P4D 0 <4> [317.128071] Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI <4> [317.128074] CPU: 1 UID: 0 PID: 1440 Comm: kunittrycatch Tainted: G U N 6.11.0-rc7-xe #1 <4> [317.128078] Tainted: [U]=USER, [N]=TEST <4> [317.128080] Hardware name: Intel Corporation Lunar Lake Client Platform/LNL-M LP5 RVP1, BIOS LNLMFWI1.R00.3221.D80.2407291239 07/29/2024 <4> [317.128082] RIP: 0010:xemigratecopy+0x66/0x13e0 [xe] <4> [317.128158] Code: 00 00 48 89 8d e0 fe ff ff 48 8b 40 10 4c 89 85 c8 fe ff ff 44 88 8d bd fe ff ff 65 48 8b 3c 25 28 00 00 00 48 89 7d d0 31 ff <8b> 79 10 48 89 85 a0 fe ff ff 48 8b 00 48 89 b5 d8 fe ff ff 83 ff <4> [317.128162] RSP: 0018:ffffc9000167f9f0 EFLAGS: 00010246 <4> [317.128164] RAX: ffff8881120d8028 RBX: ffff88814d070428 RCX: 0000000000000000 <4> [317.128166] RDX: ffff88813cb99c00 RSI: 0000000004000000 RDI: 0000000000000000 <4> [317.128168] RBP: ffffc9000167fbb8 R08: ffff88814e7b1f08 R09: 0000000000000001 <4> [317.128170] R10: 0000000000000001 R11: 0000000000000001 R12: ffff88814e7b1f08 <4> [317.128172] R13: ffff88814e7b1f08 R14: ffff88813cb99c00 R15: 0000000000000001 <4> [317.128174] FS: 0000000000000000(0000) GS:ffff88846f280000(0000) knlGS:0000000000000000 <4> [317.128176] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 <4> [317.128178] CR2: 0000000000000010 CR3: 000000011f676004 CR4: 0000000000770ef0 <4> [317.128180] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 <4> [317.128182] DR3: 0000000000000000 DR6: 00000000ffff07f0 DR7: 0000000000000400 <4> [317.128184] PKRU: 55555554 <4> [317.128185] Call Trace: <4> [317.128187] <TASK> <4> [317.128189] ? showregs+0x67/0x70 <4> [317.128194] ? diebody+0x20/0x70 <4> [317.128196] ? die+0x2b/0x40 <4> [317.128198] ? pagefaultoops+0x15f/0x4e0 <4> [317.128203] ? douseraddrfault+0x3fb/0x970 <4> [317.128205] ? lockacquire+0xc7/0x2e0 <4> [317.128209] ? excpagefault+0x87/0x2b0 <4> [317.128212] ? asmexcpagefault+0x27/0x30 <4> [317.128216] ? xemigratecopy+0x66/0x13e0 [xe] <4> [317.128263] ? lockacquire+0xb9d/0x26f0 <4> [317.128265] ? lockacquire+0xb9d/0x26f0 <4> [317.128267] ? sgfreeappendtable+0x20/0x80 <4> [317.128271] ? lockacquire+0xc7/0x2e0 <4> [317.128273] ? markheldlocks+0x4d/0x80 <4> [317.128275] ? tracehardirqson+0x1e/0xd0 <4> [317.128278] ? rawspinunlockirqrestore+0x31/0x60 <4> [317.128281] ? pmruntimeresume+0x60/0xa0 <4> [317.128284] xebomove+0x682/0xc50 [xe] <4> [317.128315] ? lockisheldtype+0xaa/0x120 <4> [317.128318] ttmbohandlemovemem+0xe5/0x1a0 [ttm] <4> [317.128324] ttmbovalidate+0xd1/0x1a0 [ttm] <4> [317.128328] shrinktestrundevice+0x721/0xc10 [xe] <4> [317.128360] ? findheldlock+0x31/0x90 <4> [317.128363] ? lockrelease+0xd1/0x2a0 <4> [317.128365] ? pfxkunitgenericrunthreadfnadapter+0x10/0x10 [kunit] <4> [317.128370] xeboshrinkkunit+0x11/0x20 [xe] <4> [317.128397] kunittryruncase+0x6e/0x150 [kunit] <4> [317.128400] ? tracehardirqson+0x1e/0xd0 <4> [317.128402] ? rawspinunlockirqrestore+0x31/0x60 <4> [317.128404] kunitgenericrunthreadfnadapter+0x1e/0x40 [ku ---truncated---
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49942?
CVE-2024-49942 has been classified with a medium severity due to the potential for NULL pointer dereference leading to denial of service.
How do I fix CVE-2024-49942?
To fix CVE-2024-49942, update the Linux kernel to a version that includes the patch addressing the NULL pointer access in the xe_migrate_copy function.
Which Linux kernel versions are affected by CVE-2024-49942?
CVE-2024-49942 affects Linux kernel versions between 6.8 and 6.10.14, as well as version 6.11.0 to 6.11.3 and 6.12-rc1.
What is the nature of the vulnerability in CVE-2024-49942?
CVE-2024-49942 is a NULL pointer dereference vulnerability that can occur in the xe_migrate_copy function when the source resource is null.
Who should be concerned about CVE-2024-49942?
System administrators and users operating affected versions of the Linux kernel should be concerned about CVE-2024-49942 and apply the necessary updates.