CVE-2023-54202 (GCVE-0-2023-54202)
Vulnerability from cvelistv5
Published
2025-12-30 12:09
Modified
2026-08-05 09:18
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/i915: fix race condition UAF in i915_perf_add_config_ioctl Userspace can guess the id value and try to race oa_config object creation with config remove, resulting in a use-after-free if we dereference the object after unlocking the metrics_lock. For that reason, unlocking the metrics_lock must be done after we are done dereferencing the object. [tursulin: Manually added stable tag.] (cherry picked from commit 49f6f6483b652108bcb73accd0204a464b922395)
Impacted products
Vendor Product Version
Linux Linux Version: f89823c212246d0671cc51e69894a3df1a743aee
Version: f89823c212246d0671cc51e69894a3df1a743aee
Version: f89823c212246d0671cc51e69894a3df1a743aee
Version: f89823c212246d0671cc51e69894a3df1a743aee
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/i915/i915_perf.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "6eeb1cba4c9dc47656ea328afa34953c28783d8c",
              "status": "affected",
              "version": "f89823c212246d0671cc51e69894a3df1a743aee",
              "versionType": "git"
            },
            {
              "lessThan": "240b1502708858b5e3f10b6dc5ca3f148a322fef",
              "status": "affected",
              "version": "f89823c212246d0671cc51e69894a3df1a743aee",
              "versionType": "git"
            },
            {
              "lessThan": "7eb98f5ac551863efe8be810cea1cd5411d677b1",
              "status": "affected",
              "version": "f89823c212246d0671cc51e69894a3df1a743aee",
              "versionType": "git"
            },
            {
              "lessThan": "dc30c011469165d57af9adac5baff7d767d20e5c",
              "status": "affected",
              "version": "f89823c212246d0671cc51e69894a3df1a743aee",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/i915/i915_perf.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "lessThan": "4.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.108",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.24",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.2.*",
              "status": "unaffected",
              "version": "6.2.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.108",
                  "versionStartIncluding": "4.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.24",
                  "versionStartIncluding": "4.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.2.11",
                  "versionStartIncluding": "4.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3",
                  "versionStartIncluding": "4.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: fix race condition UAF in i915_perf_add_config_ioctl\n\nUserspace can guess the id value and try to race oa_config object creation\nwith config remove, resulting in a use-after-free if we dereference the\nobject after unlocking the metrics_lock.  For that reason, unlocking the\nmetrics_lock must be done after we are done dereferencing the object.\n\n[tursulin: Manually added stable tag.]\n(cherry picked from commit 49f6f6483b652108bcb73accd0204a464b922395)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached only through the `DRM_IOCTL_I915_PERF_ADD_CONFIG`/`REMOVE_CONFIG` ioctls on a local i915 DRM device node (`/dev/dri/renderD128`). There is no remote or network-facing path to `i915_perf_add_config_ioctl`.\nAC:L - The attacker controls both sides of the race, running the add and remove ioctls concurrently from its own threads, and `idr_alloc()` starts at 2 so the config id to target is trivially guessable rather than secret. The race can be retried without limit and without any precondition the attacker cannot influence.\nPR:L - Both ioctls are `DRM_RENDER_ALLOW`, so they require no DRM authentication or master status and are usable by any unprivileged local user holding the render node, which udev ACLs grant to logged-in users and which is exposed to sandboxed GPU processes and GPU containers. With the commonly deployed `dev.i915.perf_stream_paranoid=0` setting used by Intel GPU profiling tooling, the `perfmon_capable()` check is bypassed entirely, leaving only ordinary user access.\nUI:N - The attacker issues both ioctls itself from its own processes; no victim action, file open, or administrative operation is needed. The race is entirely self-driven.\nS:U - The use-after-free corrupts kernel slab memory within the same kernel security authority that the ioctl already executes in. No VM, IOMMU, or sandbox boundary is crossed by the flaw itself.\nC:H - The freed `struct i915_oa_config` is read after `kfree_rcu()`, and the stale `oa_config-\u003eid` is returned to userspace as the ioctl return value (with `oa_config-\u003euuid` additionally leaked to dmesg), giving a repeatable oracle for reading attacker-resprayed kernel heap contents. As a use-after-free on a kmalloc object it can be leveraged for broader kernel memory disclosure.\nI:H - This is a use-after-free on an attacker-groomable slab object whose lifetime the attacker fully controls, which is the standard starting point for heap-spray and cross-cache attacks yielding kernel write primitives. Memory corruption of this class is treated as exploitable for control-flow hijacking and thus high integrity impact.\nA:H - Dereferencing the freed `i915_oa_config` triggers a KASAN/hardened-allocator oops and, once the slab page is recycled or the object is reused, can panic or destabilise the kernel. The race can be repeated indefinitely by an unprivileged user to force the crash."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:18:00.905Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6eeb1cba4c9dc47656ea328afa34953c28783d8c"
        },
        {
          "url": "https://git.kernel.org/stable/c/240b1502708858b5e3f10b6dc5ca3f148a322fef"
        },
        {
          "url": "https://git.kernel.org/stable/c/7eb98f5ac551863efe8be810cea1cd5411d677b1"
        },
        {
          "url": "https://git.kernel.org/stable/c/dc30c011469165d57af9adac5baff7d767d20e5c"
        }
      ],
      "title": "drm/i915: fix race condition UAF in i915_perf_add_config_ioctl",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-54202",
    "datePublished": "2025-12-30T12:09:06.872Z",
    "dateReserved": "2025-12-30T12:06:44.499Z",
    "dateUpdated": "2026-08-05T09:18:00.905Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…