CVE-2024-26922 (GCVE-0-2024-26922)
Vulnerability from cvelistv5
Published
2024-04-23 13:05
Modified
2026-08-05 11:28
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.
Impacted products
Vendor Product Version
Linux Linux Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Version: dc54d3d1744d23ed0b345fd8bc1c493b74e8df44
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-04T17:14:43.597Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d4da6b084f1c5625937d49bb6722c5b4aef11b8d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f68039375d4d6d67303674c0ab2d06b7295c0ec9"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1fd7db5c16028dc07b2ceec190f2e895dddb532d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/8b12fc7b032633539acdf7864888b0ebd49e90f2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/212e3baccdb1939606420d88f7f52d346b49a284"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ef13eeca7c79136bc38e21eb67322c1cbd5c40ee"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/b1f04b9b1c5317f562a455384c5f7473e46bdbaa"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          },
          {
            "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/"
          },
          {
            "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/"
          },
          {
            "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26922",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:46:55.644106Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:15.988Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d4da6b084f1c5625937d49bb6722c5b4aef11b8d",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "f68039375d4d6d67303674c0ab2d06b7295c0ec9",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "1fd7db5c16028dc07b2ceec190f2e895dddb532d",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "8b12fc7b032633539acdf7864888b0ebd49e90f2",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "212e3baccdb1939606420d88f7f52d346b49a284",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "ef13eeca7c79136bc38e21eb67322c1cbd5c40ee",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "b1f04b9b1c5317f562a455384c5f7473e46bdbaa",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            },
            {
              "lessThan": "6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75",
              "status": "affected",
              "version": "dc54d3d1744d23ed0b345fd8bc1c493b74e8df44",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.12"
            },
            {
              "lessThan": "4.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.313",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.275",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.216",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.157",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.88",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.29",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.313",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.275",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.216",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.157",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.88",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.29",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.8",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate the parameters of bo mapping operations more clearly\n\nVerify the parameters of\namdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Triggered by the DRM_IOCTL_AMDGPU_GEM_VA ioctl on /dev/dri/renderD128 or /dev/dri/card*, which requires local access to the device node. There is no remote or adjacent-network path to amdgpu_vm_bo_clear_mappings().\nAC:L - A single ioctl with an attacker-chosen va_address/map_size pair deterministically overflows the u64 bounds check and produces a reversed range; no race, no memory-layout dependency, no timing window. The attacker fully controls both operands of the overflowing arithmetic.\nPR:L - The ioctl is DRM_AUTH|DRM_RENDER_ALLOW, so any process able to open the render node can reach it \u2014 that includes ordinary desktop users (ACL/render group), GPU-enabled containers, and sandboxed renderer processes on Android/ChromeOS. No CAP_SYS_ADMIN, no DRM_MASTER, no root required.\nUI:N - The attacker performs the entire sequence (create BO, map it, issue the crafted CLEAR) within their own process and its own amdgpu VM. No victim action or cooperation is needed.\nS:U - The corruption is confined to the kernel\u0027s own amdgpu VM structures and GPU page tables managed by the same kernel security authority. No hypervisor, IOMMU, or sandbox boundary is crossed by the flaw itself.\nC:H - The malformed split leaves overlapping GPU VA mappings with inconsistent BO offsets in vm-\u003eva, desynchronizing the driver\u0027s mapping state from the programmed PTEs, and the unvalidated range removes the max_pfn guard that keeps page-table walks in bounds. Per kernel scoring guidance, memory/page-table corruption that can be leveraged to expose memory outside the buffer object is High.\nI:H - Overlapping mappings are inserted into the VM interval tree, a mapping with start \u003e last is queued for PTE clearing, and PRT refcounts are skewed \u2014 all of which cause GPU page tables to be programmed inconsistently with the driver\u0027s view. This memory-corruption class is scored High for integrity.\nA:H - The reversed range makes amdgpu_vm_update_range() compute (last - start + 1) * AMDGPU_GPU_PAGE_SIZE as a ~2^64 underflow, driving amdgpu_vm_ptes_update()/amdgpu_vm_pt_alloc() over an ~2^60-page range while holding the VM eviction and reservation locks. The result is unbounded page-table allocation, memory exhaustion, and a soft-lockup/hang of the GPU and system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:28:20.224Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d4da6b084f1c5625937d49bb6722c5b4aef11b8d"
        },
        {
          "url": "https://git.kernel.org/stable/c/f68039375d4d6d67303674c0ab2d06b7295c0ec9"
        },
        {
          "url": "https://git.kernel.org/stable/c/1fd7db5c16028dc07b2ceec190f2e895dddb532d"
        },
        {
          "url": "https://git.kernel.org/stable/c/8b12fc7b032633539acdf7864888b0ebd49e90f2"
        },
        {
          "url": "https://git.kernel.org/stable/c/212e3baccdb1939606420d88f7f52d346b49a284"
        },
        {
          "url": "https://git.kernel.org/stable/c/ef13eeca7c79136bc38e21eb67322c1cbd5c40ee"
        },
        {
          "url": "https://git.kernel.org/stable/c/b1f04b9b1c5317f562a455384c5f7473e46bdbaa"
        },
        {
          "url": "https://git.kernel.org/stable/c/6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75"
        }
      ],
      "title": "drm/amdgpu: validate the parameters of bo mapping operations more clearly",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26922",
    "datePublished": "2024-04-23T13:05:04.243Z",
    "dateReserved": "2024-02-19T14:20:24.194Z",
    "dateUpdated": "2026-08-05T11:28:20.224Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d4da6b084f1c5625937d49bb6722c5b4aef11b8d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/f68039375d4d6d67303674c0ab2d06b7295c0ec9\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/1fd7db5c16028dc07b2ceec190f2e895dddb532d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/8b12fc7b032633539acdf7864888b0ebd49e90f2\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/212e3baccdb1939606420d88f7f52d346b49a284\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ef13eeca7c79136bc38e21eb67322c1cbd5c40ee\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/b1f04b9b1c5317f562a455384c5f7473e46bdbaa\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/\"}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/\"}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-04T17:14:43.597Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26922\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:46:55.644106Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:15.804Z\"}}], \"cna\": {\"title\": \"drm/amdgpu: validate the parameters of bo mapping operations more clearly\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - Triggered by the DRM_IOCTL_AMDGPU_GEM_VA ioctl on /dev/dri/renderD128 or /dev/dri/card*, which requires local access to the device node. There is no remote or adjacent-network path to amdgpu_vm_bo_clear_mappings().\\nAC:L - A single ioctl with an attacker-chosen va_address/map_size pair deterministically overflows the u64 bounds check and produces a reversed range; no race, no memory-layout dependency, no timing window. The attacker fully controls both operands of the overflowing arithmetic.\\nPR:L - The ioctl is DRM_AUTH|DRM_RENDER_ALLOW, so any process able to open the render node can reach it \\u2014 that includes ordinary desktop users (ACL/render group), GPU-enabled containers, and sandboxed renderer processes on Android/ChromeOS. No CAP_SYS_ADMIN, no DRM_MASTER, no root required.\\nUI:N - The attacker performs the entire sequence (create BO, map it, issue the crafted CLEAR) within their own process and its own amdgpu VM. No victim action or cooperation is needed.\\nS:U - The corruption is confined to the kernel\u0027s own amdgpu VM structures and GPU page tables managed by the same kernel security authority. No hypervisor, IOMMU, or sandbox boundary is crossed by the flaw itself.\\nC:H - The malformed split leaves overlapping GPU VA mappings with inconsistent BO offsets in vm-\u003eva, desynchronizing the driver\u0027s mapping state from the programmed PTEs, and the unvalidated range removes the max_pfn guard that keeps page-table walks in bounds. Per kernel scoring guidance, memory/page-table corruption that can be leveraged to expose memory outside the buffer object is High.\\nI:H - Overlapping mappings are inserted into the VM interval tree, a mapping with start \u003e last is queued for PTE clearing, and PRT refcounts are skewed \\u2014 all of which cause GPU page tables to be programmed inconsistently with the driver\u0027s view. This memory-corruption class is scored High for integrity.\\nA:H - The reversed range makes amdgpu_vm_update_range() compute (last - start + 1) * AMDGPU_GPU_PAGE_SIZE as a ~2^64 underflow, driving amdgpu_vm_ptes_update()/amdgpu_vm_pt_alloc() over an ~2^60-page range while holding the VM eviction and reservation locks. The result is unbounded page-table allocation, memory exhaustion, and a soft-lockup/hang of the GPU and system.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"d4da6b084f1c5625937d49bb6722c5b4aef11b8d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"f68039375d4d6d67303674c0ab2d06b7295c0ec9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"1fd7db5c16028dc07b2ceec190f2e895dddb532d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"8b12fc7b032633539acdf7864888b0ebd49e90f2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"212e3baccdb1939606420d88f7f52d346b49a284\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"ef13eeca7c79136bc38e21eb67322c1cbd5c40ee\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"b1f04b9b1c5317f562a455384c5f7473e46bdbaa\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dc54d3d1744d23ed0b345fd8bc1c493b74e8df44\", \"lessThan\": \"6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.12\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.12\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.313\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.275\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.216\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.157\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.88\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.29\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.8\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d4da6b084f1c5625937d49bb6722c5b4aef11b8d\"}, {\"url\": \"https://git.kernel.org/stable/c/f68039375d4d6d67303674c0ab2d06b7295c0ec9\"}, {\"url\": \"https://git.kernel.org/stable/c/1fd7db5c16028dc07b2ceec190f2e895dddb532d\"}, {\"url\": \"https://git.kernel.org/stable/c/8b12fc7b032633539acdf7864888b0ebd49e90f2\"}, {\"url\": \"https://git.kernel.org/stable/c/212e3baccdb1939606420d88f7f52d346b49a284\"}, {\"url\": \"https://git.kernel.org/stable/c/ef13eeca7c79136bc38e21eb67322c1cbd5c40ee\"}, {\"url\": \"https://git.kernel.org/stable/c/b1f04b9b1c5317f562a455384c5f7473e46bdbaa\"}, {\"url\": \"https://git.kernel.org/stable/c/6fef2d4c00b5b8561ad68dd2b68173f5c6af1e75\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/amdgpu: validate the parameters of bo mapping operations more clearly\\n\\nVerify the parameters of\\namdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.313\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.275\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.216\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.157\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.88\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.29\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.8\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"4.12\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:28:20.224Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26922\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:28:20.224Z\", \"dateReserved\": \"2024-02-19T14:20:24.194Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-23T13:05:04.243Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…