CVE-2024-44978

HIGH

Linux Kernel 6.8-6.10.6 - Use-After-Free in drm/xe Job Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Free job before xe_exec_queue_put Free job depends on job->vm being valid, the last xe_exec_queue_put can destroy the VM. Prevent UAF by freeing job before xe_exec_queue_put. (cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (9)
linux/Kernel 6.8.0 - 6.10.7linux
Linux/Linux < 6.8
Linux/Linux 6.10.7 - 6.10.*
Linux/Linux 6.11
Linux/Linux 6.8
Linux/Linux dd08ebf6c3525a7ea2186e636df064ea47281987 - 98aa0330f200b9b8fb9e1298e006eda57a13351c
Linux/Linux dd08ebf6c3525a7ea2186e636df064ea47281987 - 9e7f30563677fbeff62d368d5d2a5ac7aaa9746a
linux/linux_kernel 6.11 rc1 (4 CPE variants)
linux/linux_kernel 6.8 - 6.10.7
Published Sep 04, 2024
Tracked Since Feb 18, 2026