cbcvebase.
CVE-2024-27411
published 2024-05-17

CVE-2024-27411: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: keep DMA buffers required for suspend/resume Nouveau deallocates a few buffers…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: keep DMA buffers required for suspend/resume Nouveau deallocates a few buffers post GPU init which are required for GPU suspend/resume to function correctly. This is likely not as big an issue on systems where the NVGPU is the only GPU, but on multi-GPU set ups it leads to a regression where the kernel module errors and results in a system-wide rendering freeze. This commit addresses that regression by moving the two buffers required for suspend and resume to be deallocated at driver unload instead of post init.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.9-1 (forky)linux 6.7.9-1 (forky)
linuxlinux>= 042b5f83841fbf7ce39474412db3b5e4765a7ea7 < f6ecfdad359a01c7fd8a3bcfde3ef0acdf107e6ef6ecfdad359a01c7fd8a3bcfde3ef0acdf107e6e
linuxlinux>= 6.7.6 < 6.7.96.7.9
linuxlinux>= 6190d4c08897d748dd25f0b78267a90aa1694e15 < be00e15b240ed71fc30c0576af7ab670c8271661be00e15b240ed71fc30c0576af7ab670c8271661
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 0 < 6.7.9-16.7.9-1
linuxlinux_kernel>= 6.7.6 < 6.7.96.7.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.