{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-49865", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-10-21T12:17:06.017Z", "datePublished": "2024-10-21T18:01:08.620Z", "dateUpdated": "2026-08-05T11:40:13.294Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:40:13.294Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/vm: move xa_alloc to prevent UAF\n\nEvil user can guess the next id of the vm before the ioctl completes and\nthen call vm destroy ioctl to trigger UAF since create ioctl is still\nreferencing the same vm. Move the xa_alloc all the way to the end to\nprevent this.\n\nv2:\n - Rebase\n\n(cherry picked from commit dcfd3971327f3ee92765154baebbaece833d3ca9)" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is reached through the DRM_IOCTL_XE_VM_CREATE / DRM_IOCTL_XE_VM_DESTROY ioctls on the xe render node (/dev/dri/renderD*), which requires local access to the system. There is no network or remote path to this code.\nAC:L - The attacker controls both sides of the race — one thread issues VM_CREATE while another spams VM_DESTROY on the next id, which is deterministic because xef->vm.xa is XA_FLAGS_ALLOC1 (ids 1,2,3...). The window spans a down_write and a GFP_KERNEL allocation, and failed attempts can be retried indefinitely at no cost.\nPR:L - Both ioctls are marked DRM_RENDER_ALLOW with no capability check, so any unprivileged local user holding an fd on the render node (normal desktop/Wayland sessions, Android apps, containers with the GPU device exposed) can trigger it. No root or CAP_SYS_ADMIN is needed.\nUI:N - The attacker drives both racing threads entirely from its own process; no victim action, no privileged user's involvement and no special system state is required.\nS:U - The use-after-free corrupts kernel heap memory and is exploited within the kernel's own security authority — there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed struct xe_vm is read after free (vm->pt_root[id]->bo, vm->xef->client) and a dangling pointer to it persists in the global xe->usm.asid_to_vm xarray, which the GT page-fault handler later dereferences; after slab reclaim this yields attacker-influenced pointer dereferences usable to disclose arbitrary kernel memory.\nI:H - The create path writes into the freed object (vm->usm.asid = asid, vm->xef = xe_file_get(xef)) and installs a stale pointer that is later used with xe_vm_get() and function-pointer-bearing fields (vm->pt_ops, gpuvm ops), giving heap-spray-assisted write and control-flow hijack primitives.\nA:H - Use-after-free of a large, pointer-dense structure reliably causes kernel oops/panic and GPU state corruption, and the permanently dangling asid_to_vm entry can crash the machine later from the page-fault handler." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/gpu/drm/xe/xe_vm.c" ], "versions": [ { "version": "dd08ebf6c3525a7ea2186e636df064ea47281987", "lessThan": "09cf8901fc0225898311b375cfcc67bae37ed5da", "status": "affected", "versionType": "git" }, { "version": "dd08ebf6c3525a7ea2186e636df064ea47281987", "lessThan": "74231870cf4976f69e83aa24f48edb16619f652f", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/gpu/drm/xe/xe_vm.c" ], "versions": [ { "version": "6.8", "status": "affected" }, { "version": "0", "lessThan": "6.8", "status": "unaffected", "versionType": "semver" }, { "version": "6.11.3", "lessThanOrEqual": "6.11.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.11.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.8", "versionEndExcluding": "6.12" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/09cf8901fc0225898311b375cfcc67bae37ed5da" }, { "url": "https://git.kernel.org/stable/c/74231870cf4976f69e83aa24f48edb16619f652f" } ], "title": "drm/xe/vm: move xa_alloc to prevent UAF", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-49865", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-10-22T13:47:46.140074Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-22T13:48:52.775Z" } } ] } }