cbcvebase.
CVE-2024-50096
published 2024-11-05

CVE-2024-50096: In the Linux kernel, the following vulnerability has been resolved: nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error The…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error The `nouveau_dmem_copy_one` function ensures that the copy push command is sent to the device firmware but does not track whether it was executed successfully. In the case of a copy error (e.g., firmware or hardware failure), the copy push command will be sent via the firmware channel, and `nouveau_dmem_copy_one` will likely report success, leading to the `migrate_to_ram` function returning a dirty HIGH_USER page to the user. This can result in a security vulnerability, as a HIGH_USER page that may contain sensitive or corrupted data could be returned to the user. To prevent this vulnerability, we allocate a zero page. Thus, in case of an error, a non-dirty (zero) page will be returned to the user.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < fd9bb7e996bab9b9049fffe3f3d3b50dee191d27fd9bb7e996bab9b9049fffe3f3d3b50dee191d27
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < 73f75d2b5aee5a735cf64b8ab4543d5c20dbbdd973f75d2b5aee5a735cf64b8ab4543d5c20dbbdd9
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < 8c3de9282dde21ce3c1bf1bde3166a4510547aa98c3de9282dde21ce3c1bf1bde3166a4510547aa9
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < 614bfb2050982d23d53d0d51c4079dba0437c883614bfb2050982d23d53d0d51c4079dba0437c883
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < 697e3ddcf1f8b68bd531fc34eead27c000bdf3e1697e3ddcf1f8b68bd531fc34eead27c000bdf3e1
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < ab4d113b6718b076046018292f821d5aa4b844f8ab4d113b6718b076046018292f821d5aa4b844f8
linuxlinux>= 5be73b690875f7eb2d2defb54ccd7f2f12074984 < 835745a377a4519decd1a36d6b926e369b3033e2835745a377a4519decd1a36d6b926e369b3033e2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.1 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 5.5 < 5.10.2275.10.227
linuxlinux_kernel>= 6.2 < 6.6.576.6.57

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.