CVE-2024-46709

MEDIUM

Linux Kernel - Denial of Service via DRM vmwgfx Prime External Buffer Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix prime with external buffers Make sure that for external buffers mapping goes through the dma_buf interface instead of trying to access pages directly. External buffers might not provide direct access to readable/writable pages so to make sure the bo's created from external dma_bufs can be read dma_buf interface has to be used. Fixes crashes in IGT's kms_prime with vgem. Regular desktop usage won't trigger this due to the fact that virtual machines will not have multiple GPUs but it enables better test coverage in IGT.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel < 6.6.49linux
linux/Kernel 6.7.0 - 6.10.8linux
Linux/Linux < 6.9
Linux/Linux 2cdb71c975a10b8774fcd199f16f9ea88948de50
Linux/Linux 6.10.8 - 6.10.*
Linux/Linux 6.11
Linux/Linux 6.6.29 - 6.6.49
Linux/Linux 6.6.49 - 6.6.*
Linux/Linux 6.8.8 - 6.9
Linux/Linux 6.9
... and 5 more
Published Sep 13, 2024
Tracked Since Feb 18, 2026