CVE-2022-49963

MEDIUM

Linux Kernel 5.19-5.19.7 - Integer Overflow and Improper Page Copy in DRM i915 TTM CCS Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/i915/ttm: fix CCS handling Crucible + recent Mesa seems to sometimes hit: GEM_BUG_ON(num_ccs_blks > NUM_CCS_BLKS_PER_XFER) And it looks like we can also trigger this with gem_lmem_swapping, if we modify the test to use slightly larger object sizes. Looking closer it looks like we have the following issues in migrate_copy(): - We are using plain integer in various places, which we can easily overflow with a large object. - We pass the entire object size (when the src is lmem) into emit_pte() and then try to copy it, which doesn't work, since we only have a few fixed sized windows in which to map the pages and perform the copy. With an object > 8M we therefore aren't properly copying the pages. And then with an object > 64M we trigger the GEM_BUG_ON(num_ccs_blks > NUM_CCS_BLKS_PER_XFER). So it looks like our copy handling for any object > 8M (which is our CHUNK_SZ) is currently broken on DG2. Testcase: igt@gem_lmem_swapping (cherry picked from commit 8676145eb2f53a9940ff70910caf0125bd8a4bc2)

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 5.19.0 - 5.19.8linux
Linux/Linux < 5.19
Linux/Linux 5.19
Linux/Linux 5.19.8 - 5.19.*
Linux/Linux 6.0
Linux/Linux da0595ae91da837929a00470ab40546090e5b9ae - 8d905254162965c8e6be697d82c7dbf5d08f574d
Linux/Linux da0595ae91da837929a00470ab40546090e5b9ae - 97434cb55bd884bd268626ec41489f79b261b2d4
linux/linux_kernel 6.0 rc1 (3 CPE variants)
linux/linux_kernel 5.19 - 5.19.8
Published Jun 18, 2025
Tracked Since Feb 18, 2026