CVE-2024-50187 (GCVE-0-2024-50187)
Vulnerability from cvelistv5
Published
2024-11-08 05:38
Modified
2026-08-05 11:42
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Stop the active perfmon before being destroyed Upon closing the file descriptor, the active performance monitor is not stopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`, the active performance monitor's pointer (`vc4->active_perfmon`) is still retained. If we open a new file descriptor and submit a few jobs with performance monitors, the driver will attempt to stop the active performance monitor using the stale pointer in `vc4->active_perfmon`. However, this pointer is no longer valid because the previous process has already terminated, and all performance monitors associated with it have been destroyed and freed. To fix this, when the active performance monitor belongs to a given process, explicitly stop it before destroying and freeing it.
Impacted products
Vendor Product Version
Linux Linux Version: 65101d8c9108201118efa7e08f4e2c57f438deb9
Version: 65101d8c9108201118efa7e08f4e2c57f438deb9
Version: 65101d8c9108201118efa7e08f4e2c57f438deb9
Version: 65101d8c9108201118efa7e08f4e2c57f438deb9
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-50187",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T20:18:31.290381Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T20:27:08.997Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:26:40.257Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/vc4/vc4_perfmon.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "75452da51e2403e14be007df80d133e1443fc967",
              "status": "affected",
              "version": "65101d8c9108201118efa7e08f4e2c57f438deb9",
              "versionType": "git"
            },
            {
              "lessThan": "937943c042503dc6087438bf3557f9057a588ba0",
              "status": "affected",
              "version": "65101d8c9108201118efa7e08f4e2c57f438deb9",
              "versionType": "git"
            },
            {
              "lessThan": "c9adba739d5f7cdc47a7754df4a17b47b1ecf513",
              "status": "affected",
              "version": "65101d8c9108201118efa7e08f4e2c57f438deb9",
              "versionType": "git"
            },
            {
              "lessThan": "0b2ad4f6f2bec74a5287d96cb2325a5e11706f22",
              "status": "affected",
              "version": "65101d8c9108201118efa7e08f4e2c57f438deb9",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/vc4/vc4_perfmon.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.17"
            },
            {
              "lessThan": "4.17",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.57",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "4.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.57",
                  "versionStartIncluding": "4.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.4",
                  "versionStartIncluding": "4.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "4.17",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Stop the active perfmon before being destroyed\n\nUpon closing the file descriptor, the active performance monitor is not\nstopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`,\nthe active performance monitor\u0027s pointer (`vc4-\u003eactive_perfmon`) is still\nretained.\n\nIf we open a new file descriptor and submit a few jobs with performance\nmonitors, the driver will attempt to stop the active performance monitor\nusing the stale pointer in `vc4-\u003eactive_perfmon`. However, this pointer\nis no longer valid because the previous process has already terminated,\nand all performance monitors associated with it have been destroyed and\nfreed.\n\nTo fix this, when the active performance monitor belongs to a given\nprocess, explicitly stop it before destroying and freeing it."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Triggering requires issuing VC4_PERFMON_CREATE and VC4_SUBMIT_CL ioctls on the local DRM device node /dev/dri/renderD128 and then closing the file descriptor. There is no network or adjacent-network path to the vc4 perfmon code.\nAC:L - The attacker fully controls every step \u2014 create perfmon, submit a job with it, submit a second job without it so the IRQ stop path is skipped, then close the fd \u2014 producing the dangling vc4-\u003eactive_perfmon deterministically with no race to win and no attacker-uncontrollable precondition. Heap reuse of the freed slot is likewise attacker-driven via repeated VC4_PERFMON_CREATE allocations of the same size class.\nPR:L - All required ioctls (VC4_PERFMON_CREATE, VC4_SUBMIT_CL) are marked DRM_RENDER_ALLOW with no capability check, so any unprivileged local user holding the render node \u2014 the default for logged-in desktop users on Raspberry Pi OS and for GPU-passthrough containers/sandboxes on Pi-based edge devices \u2014 can reach it.\nUI:N - The entire sequence is performed by the attacker\u0027s own process; no action by any other user or administrator is needed.\nS:U - The freed object, the stale pointer and all resulting corruption live within the kernel\u0027s own security authority on the affected system; no VM, IOMMU or hypervisor boundary is crossed.\nC:H - A pointer to freed heap memory is retained in device-global state, which per use-after-free scoring gives an attacker-influenced read primitive over reallocated kernel memory. Concretely, when a sprayed perfmon reuses the freed address the start path is skipped so hardware counters are never re-armed, and vc4_perfmon_stop(capture=true) hands the attacker V3D performance-counter values accumulated from other processes\u0027 and the compositor\u0027s GPU workloads via VC4_PERFMON_GET_VALUES.\nI:H - This is a CWE-416 dangling pointer into the kmalloc heap held in a long-lived, cross-process structure, which per use-after-free scoring is treated as High. The stale pointer corrupts driver-global state and another process\u0027s perfmon counter data, and leaves the V3D_PCTRE hardware counter enable register in an attacker-chosen state.\nA:H - The bug drives WARN_ON_ONCE splats in vc4_perfmon_start()/stop() from IRQ context, which is an immediate kernel panic on the panic_on_warn configurations common in hardened and appliance deployments. Even without that, vc4-\u003eactive_perfmon is wedged permanently non-NULL with hardware counters left running, denying the GPU perfmon path to every client until reboot."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:42:22.877Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/75452da51e2403e14be007df80d133e1443fc967"
        },
        {
          "url": "https://git.kernel.org/stable/c/937943c042503dc6087438bf3557f9057a588ba0"
        },
        {
          "url": "https://git.kernel.org/stable/c/c9adba739d5f7cdc47a7754df4a17b47b1ecf513"
        },
        {
          "url": "https://git.kernel.org/stable/c/0b2ad4f6f2bec74a5287d96cb2325a5e11706f22"
        }
      ],
      "title": "drm/vc4: Stop the active perfmon before being destroyed",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-50187",
    "datePublished": "2024-11-08T05:38:28.194Z",
    "dateReserved": "2024-10-21T19:36:19.967Z",
    "dateUpdated": "2026-08-05T11:42:22.877Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-50187\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T20:18:31.290381Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T15:20:41.049Z\"}}], \"cna\": {\"title\": \"drm/vc4: Stop the active perfmon before being destroyed\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"65101d8c9108201118efa7e08f4e2c57f438deb9\", \"lessThan\": \"75452da51e2403e14be007df80d133e1443fc967\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"65101d8c9108201118efa7e08f4e2c57f438deb9\", \"lessThan\": \"937943c042503dc6087438bf3557f9057a588ba0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"65101d8c9108201118efa7e08f4e2c57f438deb9\", \"lessThan\": \"c9adba739d5f7cdc47a7754df4a17b47b1ecf513\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"65101d8c9108201118efa7e08f4e2c57f438deb9\", \"lessThan\": \"0b2ad4f6f2bec74a5287d96cb2325a5e11706f22\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/gpu/drm/vc4/vc4_perfmon.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.17\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.17\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.57\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/gpu/drm/vc4/vc4_perfmon.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/75452da51e2403e14be007df80d133e1443fc967\"}, {\"url\": \"https://git.kernel.org/stable/c/937943c042503dc6087438bf3557f9057a588ba0\"}, {\"url\": \"https://git.kernel.org/stable/c/c9adba739d5f7cdc47a7754df4a17b47b1ecf513\"}, {\"url\": \"https://git.kernel.org/stable/c/0b2ad4f6f2bec74a5287d96cb2325a5e11706f22\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ndrm/vc4: Stop the active perfmon before being destroyed\\n\\nUpon closing the file descriptor, the active performance monitor is not\\nstopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`,\\nthe active performance monitor\u0027s pointer (`vc4-\u003eactive_perfmon`) is still\\nretained.\\n\\nIf we open a new file descriptor and submit a few jobs with performance\\nmonitors, the driver will attempt to stop the active performance monitor\\nusing the stale pointer in `vc4-\u003eactive_perfmon`. However, this pointer\\nis no longer valid because the previous process has already terminated,\\nand all performance monitors associated with it have been destroyed and\\nfreed.\\n\\nTo fix this, when the active performance monitor belongs to a given\\nprocess, explicitly stop it before destroying and freeing it.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"4.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.57\", \"versionStartIncluding\": \"4.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.4\", \"versionStartIncluding\": \"4.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"4.17\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:48:13.504Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-50187\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-10-01T20:27:08.997Z\", \"dateReserved\": \"2024-10-21T19:36:19.967Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-11-08T05:38:28.194Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…