CVE-2024-50090 (GCVE-0-2024-50090)
Vulnerability from cvelistv5
Published
2024-11-05 17:04
Modified
2026-08-05 11:41
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix overflow in oa batch buffer By default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch buffer, this is not a problem if batch buffer is only used once but oa reuses the batch buffer for the same metric and at each call it appends a MI_BATCH_BUFFER_END, printing the warning below and then overflowing. [ 381.072016] ------------[ cut here ]------------ [ 381.072019] xe 0000:00:02.0: [drm] Assertion `bb->len * 4 + bb_prefetch(q->gt) <= size` failed! platform: LUNARLAKE subplatform: 1 graphics: Xe2_LPG / Xe2_HPG 20.04 step B0 media: Xe2_LPM / Xe2_HPM 20.00 step B0 tile: 0 VRAM 0 B GT: 0 type 1 So here checking if batch buffer already have MI_BATCH_BUFFER_END if not append it. v2: - simply fix, suggestion from Ashutosh (cherry picked from commit 9ba0e0f30ca42a98af3689460063edfb6315718a)
Impacted products
Vendor Product Version
Linux Linux Version: dd08ebf6c3525a7ea2186e636df064ea47281987
Version: dd08ebf6c3525a7ea2186e636df064ea47281987
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-50090",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-18T15:56:39.428028Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-120",
                "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-18T15:57:57.426Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_bb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "bcb5be3421705e682b0b32073ad627056d6bc2a2",
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "versionType": "git"
            },
            {
              "lessThan": "6c10ba06bb1b48acce6d4d9c1e33beb9954f1788",
              "status": "affected",
              "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/xe/xe_bb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.4",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix overflow in oa batch buffer\n\nBy default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch\nbuffer, this is not a problem if batch buffer is only used once but\noa reuses the batch buffer for the same metric and at each call\nit appends a MI_BATCH_BUFFER_END, printing the warning below and then\noverflowing.\n\n[  381.072016] ------------[ cut here ]------------\n[  381.072019] xe 0000:00:02.0: [drm] Assertion `bb-\u003elen * 4 + bb_prefetch(q-\u003egt) \u003c= size` failed!\n               platform: LUNARLAKE subplatform: 1\n               graphics: Xe2_LPG / Xe2_HPG 20.04 step B0\n               media: Xe2_LPM / Xe2_HPM 20.00 step B0\n               tile: 0 VRAM 0 B\n               GT: 0 type 1\n\nSo here checking if batch buffer already have MI_BATCH_BUFFER_END if\nnot append it.\n\nv2:\n- simply fix, suggestion from Ashutosh\n\n(cherry picked from commit 9ba0e0f30ca42a98af3689460063edfb6315718a)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached through the xe DRM render node (`/dev/dri/renderD*`) via the OA stream open ioctl followed by `DRM_XE_OBSERVATION_IOCTL_CONFIG` on the returned fd. This requires local access to the GPU device node; there is no remote or adjacent-network path.\nAC:L - Triggering is fully deterministic \u2014 the attacker opens one OA stream and loops the CONFIG ioctl alternating between two metric sets, with `bb-\u003elen` incrementing by exactly one dword per call, so the overflow offset is precisely attacker-chosen and no race or unknown memory layout is involved. CONFIG_DRM_XE is the default driver for all modern Intel graphics (Meteor Lake, Lunar Lake, DG2/Arc, Battlemage) in distro kernels.\nPR:L - Only an unprivileged local account with render-node access and an exec queue is needed: the query-sampling path sets `privileged_op = false` (`xe_oa.c:1826`), bypassing the `perfmon_capable()` gate at stream open, and `xe_oa_ioctl()`/`xe_oa_config_locked()` perform no capability check at all. Render nodes are world-accessible or render-group accessible on common distros and reachable by ordinary apps on Android/ChromeOS.\nUI:N - The attacker performs the entire sequence \u2014 open stream, loop the config ioctl \u2014 within their own process. No victim action is required.\nS:U - The out-of-bounds write and its consequences are confined to kernel memory managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed by the flaw itself.\nC:H - The overflow writes into the shared 1 MB `kernel_bb_pool` holding live `xe_migrate` command streams; a stray MI_BATCH_BUFFER_END truncates a BO clear/copy batch, leaving stale memory contents exposed to another client, or corrupts a PTE-emitting batch so GPU page tables map arbitrary memory readable by attacker GPU work. On discrete GPUs the write lands in a `kvzalloc()`\u0027d kernel heap buffer, giving OOB access to adjacent kernel objects.\nI:H - This is an unbounded out-of-bounds kernel write of a fixed dword (0x05000000) at an offset the attacker selects exactly by iteration count, hitting vmap\u0027d BO pages on integrated GPUs and the kernel heap on discrete GPUs. It also rewrites GPU command streams that the engine executes with full GGTT access, making control-flow and page-table corruption achievable.\nA:H - The reported symptom is a driver assertion failure and buffer overflow; continued iteration corrupts in-flight kernel batch buffers causing GPU hangs and device wedging, and writing past the pool mapping produces a kernel oops/panic."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:41:34.890Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bcb5be3421705e682b0b32073ad627056d6bc2a2"
        },
        {
          "url": "https://git.kernel.org/stable/c/6c10ba06bb1b48acce6d4d9c1e33beb9954f1788"
        }
      ],
      "title": "drm/xe/oa: Fix overflow in oa batch buffer",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-50090",
    "datePublished": "2024-11-05T17:04:54.546Z",
    "dateReserved": "2024-10-21T19:36:19.942Z",
    "dateUpdated": "2026-08-05T11:41:34.890Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-50090\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-02-18T15:56:39.428028Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-120\", \"description\": \"CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-02-18T15:55:09.569Z\"}}], \"cna\": {\"title\": \"drm/xe/oa: Fix overflow in oa batch buffer\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached through the xe DRM render node (`/dev/dri/renderD*`) via the OA stream open ioctl followed by `DRM_XE_OBSERVATION_IOCTL_CONFIG` on the returned fd. This requires local access to the GPU device node; there is no remote or adjacent-network path.\\nAC:L - Triggering is fully deterministic \\u2014 the attacker opens one OA stream and loops the CONFIG ioctl alternating between two metric sets, with `bb-\u003elen` incrementing by exactly one dword per call, so the overflow offset is precisely attacker-chosen and no race or unknown memory layout is involved. CONFIG_DRM_XE is the default driver for all modern Intel graphics (Meteor Lake, Lunar Lake, DG2/Arc, Battlemage) in distro kernels.\\nPR:L - Only an unprivileged local account with render-node access and an exec queue is needed: the query-sampling path sets `privileged_op = false` (`xe_oa.c:1826`), bypassing the `perfmon_capable()` gate at stream open, and `xe_oa_ioctl()`/`xe_oa_config_locked()` perform no capability check at all. Render nodes are world-accessible or render-group accessible on common distros and reachable by ordinary apps on Android/ChromeOS.\\nUI:N - The attacker performs the entire sequence \\u2014 open stream, loop the config ioctl \\u2014 within their own process. No victim action is required.\\nS:U - The out-of-bounds write and its consequences are confined to kernel memory managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed by the flaw itself.\\nC:H - The overflow writes into the shared 1 MB `kernel_bb_pool` holding live `xe_migrate` command streams; a stray MI_BATCH_BUFFER_END truncates a BO clear/copy batch, leaving stale memory contents exposed to another client, or corrupts a PTE-emitting batch so GPU page tables map arbitrary memory readable by attacker GPU work. On discrete GPUs the write lands in a `kvzalloc()`\u0027d kernel heap buffer, giving OOB access to adjacent kernel objects.\\nI:H - This is an unbounded out-of-bounds kernel write of a fixed dword (0x05000000) at an offset the attacker selects exactly by iteration count, hitting vmap\u0027d BO pages on integrated GPUs and the kernel heap on discrete GPUs. It also rewrites GPU command streams that the engine executes with full GGTT access, making control-flow and page-table corruption achievable.\\nA:H - The reported symptom is a driver assertion failure and buffer overflow; continued iteration corrupts in-flight kernel batch buffers causing GPU hangs and device wedging, and writing past the pool mapping produces a kernel oops/panic.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"dd08ebf6c3525a7ea2186e636df064ea47281987\", \"lessThan\": \"bcb5be3421705e682b0b32073ad627056d6bc2a2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd08ebf6c3525a7ea2186e636df064ea47281987\", \"lessThan\": \"6c10ba06bb1b48acce6d4d9c1e33beb9954f1788\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/gpu/drm/xe/xe_bb.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.11.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/xe/xe_bb.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/bcb5be3421705e682b0b32073ad627056d6bc2a2\"}, {\"url\": \"https://git.kernel.org/stable/c/6c10ba06bb1b48acce6d4d9c1e33beb9954f1788\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/xe/oa: Fix overflow in oa batch buffer\\n\\nBy default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch\\nbuffer, this is not a problem if batch buffer is only used once but\\noa reuses the batch buffer for the same metric and at each call\\nit appends a MI_BATCH_BUFFER_END, printing the warning below and then\\noverflowing.\\n\\n[  381.072016] ------------[ cut here ]------------\\n[  381.072019] xe 0000:00:02.0: [drm] Assertion `bb-\u003elen * 4 + bb_prefetch(q-\u003egt) \u003c= size` failed!\\n               platform: LUNARLAKE subplatform: 1\\n               graphics: Xe2_LPG / Xe2_HPG 20.04 step B0\\n               media: Xe2_LPM / Xe2_HPM 20.00 step B0\\n               tile: 0 VRAM 0 B\\n               GT: 0 type 1\\n\\nSo here checking if batch buffer already have MI_BATCH_BUFFER_END if\\nnot append it.\\n\\nv2:\\n- simply fix, suggestion from Ashutosh\\n\\n(cherry picked from commit 9ba0e0f30ca42a98af3689460063edfb6315718a)\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.4\", \"versionStartIncluding\": \"6.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"6.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:41:34.890Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-50090\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:41:34.890Z\", \"dateReserved\": \"2024-10-21T19:36:19.942Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-11-05T17:04:54.546Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…