CVE-2024-46710

MEDIUM

Linux Kernel 5.19-6.10.7 - Use-After-Free in DRM vmwgfx Buffer Mapping

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to read and compare the cursor buffer. These maps can race with each other in simple scenario where: a) buffer "a" mapped for update b) buffer "a" mapped for compare c) do the compare d) unmap "a" for compare e) update the cursor f) unmap "a" for update At step "e" the buffer has been unmapped and the read contents is bogus. Prevent unmapping of active read buffers by simply keeping a count of how many paths have currently active maps and unmap only when the count reaches 0.

Scores

CVSS v3 4.7
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel 5.19.0 - 6.1.113linux
linux/Kernel 6.2.0 - 6.6.54linux
linux/Kernel 6.7.0 - 6.10.8linux
Linux/Linux < 5.19
Linux/Linux 485d98d472d53f9617ffdfba5e677ac29ad4fe20 - 0851b1ec650adadcaa23ec96daad95a55bf966f0
Linux/Linux 485d98d472d53f9617ffdfba5e677ac29ad4fe20 - 58a3714db4d9dcaeb9fc4905141e17b9f536c0a5
Linux/Linux 485d98d472d53f9617ffdfba5e677ac29ad4fe20 - aba07b9a0587f50e5d3346eaa19019cf3f86c0ea
Linux/Linux 485d98d472d53f9617ffdfba5e677ac29ad4fe20 - d5228d158e4c0b1663b3983044913c15c3d0135e
Linux/Linux 5.19
Linux/Linux 6.1.113 - 6.1.*
... and 5 more
Published Sep 13, 2024
Tracked Since Feb 18, 2026