CVE-2024-46866 (GCVE-0-2024-46866)
Vulnerability from cvelistv5
Published
2024-09-27 12:42
Modified
2026-08-05 11:39
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: add missing bo locking in show_meminfo() bo_meminfo() wants to inspect bo state like tt and the ttm resource, however this state can change at any point leading to stuff like NPD and UAF, if the bo lock is not held. Grab the bo lock when calling bo_meminfo(), ensuring we drop any spinlocks first. In the case of object_idr we now also need to hold a ref. v2 (MattB) - Also add xe_bo_assert_held() (cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)
Impacted products
Vendor Product Version
Linux Linux Version: 0845233388f8a26d00acf9bf230cfd4f36aa4c30
Version: 0845233388f8a26d00acf9bf230cfd4f36aa4c30
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-46866",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-29T13:40:49.646755Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-29T13:41:44.644Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_drm_client.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "abc8feacacf8fae10eecf6fea7865e8c1fee419c",
              "status": "affected",
              "version": "0845233388f8a26d00acf9bf230cfd4f36aa4c30",
              "versionType": "git"
            },
            {
              "lessThan": "94c4aa266111262c96c98f822d1bccc494786fee",
              "status": "affected",
              "version": "0845233388f8a26d00acf9bf230cfd4f36aa4c30",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_drm_client.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.11",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: add missing bo locking in show_meminfo()\n\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\nhowever this state can change at any point leading to stuff like NPD and\nUAF, if the bo lock is not held. Grab the bo lock when calling\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\nobject_idr we now also need to hold a ref.\n\nv2 (MattB)\n  - Also add xe_bo_assert_held()\n\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires opening a local Xe DRM render node (`/dev/dri/renderD128`), issuing GEM/VM/exec ioctls, and reading `/proc/\u003cpid\u003e/fdinfo/\u003cfd\u003e`; there is no remote or adjacent-network path to `show_meminfo()`.\nAC:L - The attacker owns both sides of the race inside a single process \u2014 one thread loops on its own fdinfo while another loops BO validation/migration ioctls that drive `ttm_bo_move_null()`/`ttm_bo_tt_destroy()`; no condition lies outside attacker control and the SYSTEM\u2194TT move window is hit constantly on integrated Xe GPUs.\nPR:L - Only an unprivileged local account with normal GPU access is needed \u2014 the Xe driver sets DRIVER_RENDER, so the render node requires no DRM master or capability, and reading one\u0027s own `/proc/self/fdinfo` trivially satisfies PTRACE_MODE_READ.\nUI:N - The attacking process opens the device, creates the BOs, and reads its own fdinfo entirely on its own; no victim action or interaction with another user is required.\nS:U - The corruption and its effects stay within the kernel of the same machine, with no crossing of a hypervisor, IOMMU, or other security-authority boundary.\nC:H - The race yields use-after-free reads of freed `ttm_resource` and `ttm_tt` slab objects, and the values read (`res-\u003emem_type`, `tt-\u003epage_flags`) directly steer the accounting numbers printed back to userspace in fdinfo, leaking freed-heap contents; per kernel guidance a UAF is scored High.\nI:H - The commit explicitly identifies a use-after-free, which is scored High because a freed-object race on repeatedly reallocated TTM slab objects can be groomed into memory-corruption/control primitives, and the stale `mem_type` selects the accumulator slot updated with the attacker-chosen BO size.\nA:H - `resource_is_vram()` dereferences `bo-\u003ettm.resource` unconditionally, so hitting the `ttm_resource_free()` NULL window produces an immediate kernel oops, and the UAF reads add further crash paths \u2014 all repeatable at will by an unprivileged local user."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:39:08.572Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/abc8feacacf8fae10eecf6fea7865e8c1fee419c"
        },
        {
          "url": "https://git.kernel.org/stable/c/94c4aa266111262c96c98f822d1bccc494786fee"
        }
      ],
      "title": "drm/xe/client: add missing bo locking in show_meminfo()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-46866",
    "datePublished": "2024-09-27T12:42:54.381Z",
    "dateReserved": "2024-09-11T15:12:18.294Z",
    "dateUpdated": "2026-08-05T11:39:08.572Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-46866\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-29T13:40:49.646755Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-29T13:41:41.019Z\"}}], \"cna\": {\"title\": \"drm/xe/client: add missing bo locking in show_meminfo()\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"0845233388f8a26d00acf9bf230cfd4f36aa4c30\", \"lessThan\": \"abc8feacacf8fae10eecf6fea7865e8c1fee419c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0845233388f8a26d00acf9bf230cfd4f36aa4c30\", \"lessThan\": \"94c4aa266111262c96c98f822d1bccc494786fee\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/gpu/drm/xe/xe_drm_client.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.10.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/xe/xe_drm_client.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/abc8feacacf8fae10eecf6fea7865e8c1fee419c\"}, {\"url\": \"https://git.kernel.org/stable/c/94c4aa266111262c96c98f822d1bccc494786fee\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/xe/client: add missing bo locking in show_meminfo()\\n\\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\\nhowever this state can change at any point leading to stuff like NPD and\\nUAF, if the bo lock is not held. Grab the bo lock when calling\\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\\nobject_idr we now also need to hold a ref.\\n\\nv2 (MattB)\\n  - Also add xe_bo_assert_held()\\n\\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.11\", \"versionStartIncluding\": \"6.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"6.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:36:17.715Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-46866\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-04T09:36:17.715Z\", \"dateReserved\": \"2024-09-11T15:12:18.294Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-09-27T12:42:54.381Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…