CVE-2024-46712
published 2024-09-13CVE-2024-46712: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only sense if…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only sense if the host renders to them using
accelerated apis. Without 3d the entire content of dumb buffers stays
in the guest making all of the extra work they're doing to synchronize
between guest and host useless.
Configurations without 3d also tend to run with very low graphics
memory limits. The pinned console fb, mob cursors and graphical login
manager tend to run out of 16MB graphics memory that those guests use.
Fix it by making sure the coherent dumb buffers are only used on
configs with 3d enabled.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.10.9-1 (forky) | linux 6.10.9-1 (forky) |
| linux | linux | >= 6.10.4 < 6.10.8 | 6.10.8 |
| linux | linux | >= af6441e6f3d41e95bfc5bfc11960c259bb4f0f11 < c45558414b8f2e0b9dc34eb8f9d4e8359b887681 | c45558414b8f2e0b9dc34eb8f9d4e8359b887681 |
| linux | linux | >= d6667f0ddf46c671d379cd5fe66ce0a54d2a743a < e9fd436bb8fb9b9d31fdf07bbcdba6d30290c5e4 | e9fd436bb8fb9b9d31fdf07bbcdba6d30290c5e4 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.10.9-1 | 6.10.9-1 |
| linux | linux_kernel | >= 0 < 6.10.9-1 | 6.10.9-1 |
| linux | linux_kernel | >= 6.10.4 < 6.10.8 | 6.10.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/vmwgfx: Disable coherent dumb buffers without 3d
vendor_redhat·2024-09-13·CVSS 5.5
CVE-2024-46712 [MEDIUM] CWE-124 kernel: drm/vmwgfx: Disable coherent dumb buffers without 3d
kernel: drm/vmwgfx: Disable coherent dumb buffers without 3d
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only sense if the host renders to them using
accelerated apis. Without 3d the entire content of dumb buffers stays
in the guest making all of the extra work they're doing to synchronize
between guest and host useless.
Configurations without 3d also tend to run with very low graphics
memory limits. The pinned console fb, mob cursors and graphical login
manager tend to run out of 16MB graphics memory that those guests use.
Fix it by making sure the coherent dumb buffers are only used on
configs with 3d enabled.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package:
Debian
CVE-2024-46712: linux - In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx:...
vendor_debian·2024·CVSS 5.5
CVE-2024-46712 [MEDIUM] CVE-2024-46712: linux - In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx:...
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only sense if the host renders to them using accelerated apis. Without 3d the entire content of dumb buffers stays in the guest making all of the extra work they're doing to synchronize between guest and host useless. Configurations without 3d also tend to run with very low graphics memory limits. The pinned console fb, mob cursors and graphical login manager tend to run out of 16MB graphics memory that those guests use. Fix it by making sure the coherent dumb buffers are only used on configs with 3d enabled.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.9-1)
sid: resolved (fixed in 6.10.9-1)
trixie: resolved (fi
OSV
CVE-2024-46712: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only s
osv·2024-09-13·CVSS 5.5
CVE-2024-46712 [MEDIUM] CVE-2024-46712: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only s
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only sense if the host renders to them using accelerated apis. Without 3d the entire content of dumb buffers stays in the guest making all of the extra work they're doing to synchronize between guest and host useless. Configurations without 3d also tend to run with very low graphics memory limits. The pinned console fb, mob cursors and graphical login manager tend to run out of 16MB graphics memory that those guests use. Fix it by making sure the coherent dumb buffers are only used on configs with 3d enabled.
GHSA
GHSA-cp7f-67pj-cxg3: In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only
ghsa_unreviewed·2024-09-13
CVE-2024-46712 [MEDIUM] GHSA-cp7f-67pj-cxg3: In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only sense if the host renders to them using
accelerated apis. Without 3d the entire content of dumb buffers stays
in the guest making all of the extra work they're doing to synchronize
between guest and host useless.
Configurations without 3d also tend to run with very low graphics
memory limits. The pinned console fb, mob cursors and graphical login
manager tend to run out of 16MB graphics memory that those guests use.
Fix it by making sure the coherent dumb buffers are only used on
configs with 3d enabled.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-13
Published