cbcvebase.
CVE-2024-40924
published 2024-07-12

CVE-2024-40924: In the Linux kernel, the following vulnerability has been resolved: drm/i915/dpt: Make DPT object unshrinkable In some scenarios, the DPT object gets shrunk…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
21.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/i915/dpt: Make DPT object unshrinkable In some scenarios, the DPT object gets shrunk but the actual framebuffer did not and thus its still there on the DPT's vm->bound_list. Then it tries to rewrite the PTEs via a stale CPU mapping. This causes panic. [vsyrjala: Add TODO comment] (cherry picked from commit 51064d471c53dcc8eddd2333c3f1c1d9131ba36c)

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 0dc987b699ce4266450d407d6d79d41eab88c5d0 < 327280149066f0e5f2e50356b5823f76dabfe86e327280149066f0e5f2e50356b5823f76dabfe86e
linuxlinux>= 0dc987b699ce4266450d407d6d79d41eab88c5d0 < 7a9883be3b98673333eec65c4a21cc18e60292eb7a9883be3b98673333eec65c4a21cc18e60292eb
linuxlinux>= 0dc987b699ce4266450d407d6d79d41eab88c5d0 < a2552020fb714ff357182c3c179abfac2289f84da2552020fb714ff357182c3c179abfac2289f84d
linuxlinux>= 0dc987b699ce4266450d407d6d79d41eab88c5d0 < 43e2b37e2ab660c3565d4cff27922bc70e79c3f143e2b37e2ab660c3565d4cff27922bc70e79c3f1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.0 < 6.1.956.1.95
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.