CVE-2024-46709 (GCVE-0-2024-46709)
Vulnerability from cvelistv5
Published
2024-09-13 06:33
Modified
2026-08-05 11:38
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix prime with external buffers Make sure that for external buffers mapping goes through the dma_buf interface instead of trying to access pages directly. External buffers might not provide direct access to readable/writable pages so to make sure the bo's created from external dma_bufs can be read dma_buf interface has to be used. Fixes crashes in IGT's kms_prime with vgem. Regular desktop usage won't trigger this due to the fact that virtual machines will not have multiple GPUs but it enables better test coverage in IGT.
Impacted products
Vendor Product Version
Linux Linux Version: 65674218b43f2dd54587ab2b06560e17c30d8b41
Version: b32233accefff1338806f064fb9b62cf5bc0609f
Version: b32233accefff1338806f064fb9b62cf5bc0609f
Version: 2cdb71c975a10b8774fcd199f16f9ea88948de50
Version: 6.6.29   
Version: 6.8.8   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-46709",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-29T15:00:04.048988Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-29T15:00:18.143Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/vmwgfx/vmwgfx_blit.c",
            "drivers/gpu/drm/vmwgfx/vmwgfx_drv.h",
            "drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4",
              "status": "affected",
              "version": "65674218b43f2dd54587ab2b06560e17c30d8b41",
              "versionType": "git"
            },
            {
              "lessThan": "5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854",
              "status": "affected",
              "version": "b32233accefff1338806f064fb9b62cf5bc0609f",
              "versionType": "git"
            },
            {
              "lessThan": "50f1199250912568606b3778dc56646c10cb7b04",
              "status": "affected",
              "version": "b32233accefff1338806f064fb9b62cf5bc0609f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cdb71c975a10b8774fcd199f16f9ea88948de50",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.49",
              "status": "affected",
              "version": "6.6.29",
              "versionType": "semver"
            },
            {
              "lessThan": "6.9",
              "status": "affected",
              "version": "6.8.8",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/vmwgfx/vmwgfx_blit.c",
            "drivers/gpu/drm/vmwgfx/vmwgfx_drv.h",
            "drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "lessThan": "6.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.49",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.49",
                  "versionStartIncluding": "6.6.29",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.8",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.8.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix prime with external buffers\n\nMake sure that for external buffers mapping goes through the dma_buf\ninterface instead of trying to access pages directly.\n\nExternal buffers might not provide direct access to readable/writable\npages so to make sure the bo\u0027s created from external dma_bufs can be\nread dma_buf interface has to be used.\n\nFixes crashes in IGT\u0027s kms_prime with vgem. Regular desktop usage won\u0027t\ntrigger this due to the fact that virtual machines will not have\nmultiple GPUs but it enables better test coverage in IGT."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires opening the vmwgfx DRM device node and issuing local ioctls (PRIME_FD_TO_HANDLE, ADDFB2, atomic modeset/DIRTYFB/VMW_PRESENT_READBACK). There is no network-reachable path into drivers/gpu/drm/vmwgfx.\nAC:L - The attacker performs every step deterministically \u2014 create/export an external dma-buf, import it into vmwgfx, build a framebuffer, and trigger the CPU blit via a modeset or present-readback; there is no race or memory-layout condition outside the attacker\u0027s control.\nPR:L - Only local unprivileged access to /dev/dri/card0 is needed; PRIME import is DRM_RENDER_ALLOW (no auth), and DRM master is granted automatically to the first opener of a master-less node, which any seat/video-group user obtains without root.\nUI:N - The attacking process creates the external dma-buf, imports it, adds the framebuffer and drives the modeset itself. No action by another user or administrator is required.\nS:U - The invalid page mappings and memcpy corruption stay inside the guest kernel\u0027s own security authority; this is a guest DRM driver bug, not a hypervisor or IOMMU boundary crossing.\nC:H - vmw_bo_cpu_blit_line() kmap_atomic()s attacker-influenced, non-CPU-mappable page pointers derived from the imported sg table and memcpys from them into the display surface\u0027s buffer, which userspace can read back via VMW_PRESENT_READBACK \u2014 disclosing arbitrary kernel memory.\nI:H - In the readback direction the external bo is the memcpy destination, so attacker-controlled framebuffer bytes are written through those bogus page pointers into unrelated kernel memory, giving a kernel write primitive.\nA:H - The maintainer states the change \"fixes crashes in IGT\u0027s kms_prime with vgem\"; dereferencing invalid page pointers under kmap_atomic (preemption and page faults disabled) reliably oopses or panics the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:38:04.182Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4"
        },
        {
          "url": "https://git.kernel.org/stable/c/5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854"
        },
        {
          "url": "https://git.kernel.org/stable/c/50f1199250912568606b3778dc56646c10cb7b04"
        }
      ],
      "title": "drm/vmwgfx: Fix prime with external buffers",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-46709",
    "datePublished": "2024-09-13T06:33:41.392Z",
    "dateReserved": "2024-09-11T15:12:18.252Z",
    "dateUpdated": "2026-08-05T11:38:04.182Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-46709\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-29T15:00:04.048988Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-29T15:00:08.546Z\"}}], \"cna\": {\"title\": \"drm/vmwgfx: Fix prime with external buffers\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"65674218b43f2dd54587ab2b06560e17c30d8b41\", \"lessThan\": \"9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b32233accefff1338806f064fb9b62cf5bc0609f\", \"lessThan\": \"5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b32233accefff1338806f064fb9b62cf5bc0609f\", \"lessThan\": \"50f1199250912568606b3778dc56646c10cb7b04\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2cdb71c975a10b8774fcd199f16f9ea88948de50\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6.6.29\", \"lessThan\": \"6.6.49\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.8.8\", \"lessThan\": \"6.9\", \"versionType\": \"semver\"}], \"programFiles\": [\"drivers/gpu/drm/vmwgfx/vmwgfx_blit.c\", \"drivers/gpu/drm/vmwgfx/vmwgfx_drv.h\", \"drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.9\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.9\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.49\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.8\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/vmwgfx/vmwgfx_blit.c\", \"drivers/gpu/drm/vmwgfx/vmwgfx_drv.h\", \"drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4\"}, {\"url\": \"https://git.kernel.org/stable/c/5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854\"}, {\"url\": \"https://git.kernel.org/stable/c/50f1199250912568606b3778dc56646c10cb7b04\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/vmwgfx: Fix prime with external buffers\\n\\nMake sure that for external buffers mapping goes through the dma_buf\\ninterface instead of trying to access pages directly.\\n\\nExternal buffers might not provide direct access to readable/writable\\npages so to make sure the bo\u0027s created from external dma_bufs can be\\nread dma_buf interface has to be used.\\n\\nFixes crashes in IGT\u0027s kms_prime with vgem. Regular desktop usage won\u0027t\\ntrigger this due to the fact that virtual machines will not have\\nmultiple GPUs but it enables better test coverage in IGT.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.49\", \"versionStartIncluding\": \"6.6.29\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.8\", \"versionStartIncluding\": \"6.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"6.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"6.8.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-23T15:53:26.939Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-46709\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-23T15:53:26.939Z\", \"dateReserved\": \"2024-09-11T15:12:18.252Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-09-13T06:33:41.392Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…