cbcvebase.
CVE-2024-41092
published 2024-07-29

CVE-2024-41092: In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix potential UAF by revoke of fence registers CI has been sporadically…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix potential UAF by revoke of fence registers CI has been sporadically reporting the following issue triggered by igt@i915_selftest@live@hangcheck on ADL-P and similar machines: [414.049203] i915: Running intel_hangcheck_live_selftests/igt_reset_evict_fence ... [414.068804] i915 0000:00:02.0: [drm] GT0: GUC: submission enabled [414.068812] i915 0000:00:02.0: [drm] GT0: GUC: SLPC enabled [414.070354] Unable to pin Y-tiled fence; err:-4 [414.071282] i915_vma_revoke_fence:301 GEM_BUG_ON(!i915_active_is_idle(&fence->active)) ... [ 609.603992] ------------[ cut here ]------------ [ 609.603995] kernel BUG at drivers/gpu/drm/i915/gt/intel_ggtt_fencing.c:301! [ 609.604003] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI [ 609.604006] CPU: 0 PID: 268 Comm: kworker/u64:3 Tainted: G U W 6.9.0-CI_DRM_14785-g1ba62f8cea9c+ #1 [ 609.604008] Hardware name: Intel Corporation Alder Lake Client Platform/AlderLake-P DDR4 RVP, BIOS RPLPFWI1.R00.4035.A00.2301200723 01/20/2023 [ 609.604010] Workqueue: i915 __i915_gem_free_work [i915] [ 609.604149] RIP: 0010:i915_vma_revoke_fence+0x187/0x1f0 [i915] ... [ 609.604271] Call Trace: [ 609.604273] ... [ 609.604716] __i915_vma_evict+0x2e9/0x550 [i915] [ 609.604852] __i915_vma_unbind+0x7c/0x160 [i915] [ 609.604977] force_unbind+0x24/0xa0 [i915] [ 609.605098] i915_vma_destroy+0x2f/0xa0 [i915] [ 609.605210] __i915_gem_object_pages_fini+0x51/0x2f0 [i915] [ 609.605330] __i915_gem_free_objects.isra.0+0x6a/0xc0 [i915] [ 609.605440] process_scheduled_works+0x351/0x690 ... In the past, there were similar failures reported by CI from other IGT tests, observed on other platforms. Before commit 63baf4f3d587 ("drm/i915/gt: Only wait for GPU activity before unbinding a GGTT fence"), i915_vma_revoke_fence() was waiting for idleness of vma->active via fence_update(). That commit introduced vma->fence->active in order for the fence_update() to be able to wait selectively on that on

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < f771b91f21c46ad1217328d05e72a2c7e3add535f771b91f21c46ad1217328d05e72a2c7e3add535
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < 29c0fdf49078ab161570d3d1c6e13d66f182717d29c0fdf49078ab161570d3d1c6e13d66f182717d
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < ca0fabd365a27a94a36e68a7a02df8ff3c13dac6ca0fabd365a27a94a36e68a7a02df8ff3c13dac6
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < 06dec31a0a5112a91f49085e8a8fa1a82296d5c706dec31a0a5112a91f49085e8a8fa1a82296d5c7
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < 414f4a31f7a811008fd9a33b06216b060bad18fc414f4a31f7a811008fd9a33b06216b060bad18fc
linuxlinux>= 0d86ee35097ae0f1c2c50f2b8035ef480e25e4f1 < 996c3412a06578e9d779a16b9e79ace18125ab50996c3412a06578e9d779a16b9e79ace18125ab50
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.8 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.376.6.37
linuxlinux_kernel>= 6.7 < 6.9.86.9.8
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.