cbcvebase.
CVE-2024-42261
published 2024-08-17

CVE-2024-42261: In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension If userspace…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension If userspace provides an unknown or invalid handle anywhere in the handle array the rest of the driver will not handle that well. Fix it by checking handle was looked up successfully or otherwise fail the extension by jumping into the existing unwind. (cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.4-1 (forky)linux 6.10.4-1 (forky)
linuxlinux
linuxlinux>= 9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f < 5c56f104edd02a537e9327dc543574e55713e1d75c56f104edd02a537e9327dc543574e55713e1d7
linuxlinux>= 9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f < 023d22e8bb0cdd6900382ad1ed06df3b6c2ea791023d22e8bb0cdd6900382ad1ed06df3b6c2ea791
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.8 < 6.10.46.10.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.