7.8

CVE-2023-52930

drm/i915: Fix potential bit_17 double-free

In the Linux kernel, the following vulnerability has been resolved:

drm/i915: Fix potential bit_17 double-free

A userspace with multiple threads racing I915_GEM_SET_TILING to set the
tiling to I915_TILING_NONE could trigger a double free of the bit_17
bitmask.  (Or conversely leak memory on the transition to tiled.)  Move
allocation/free'ing of the bitmask within the section protected by the
obj lock.

[tursulin: Correct fixes tag and added cc stable.]
(cherry picked from commit 10e0cbaaf1104f449d695c80bcacf930dcd3c42e)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.168
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.93
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.11
Linux ≫ Linux Kernel Version 6.2 Update rc1
Linux ≫ Linux Kernel Version 6.2 Update rc2
Linux ≫ Linux Kernel Version 6.2 Update rc3
Linux ≫ Linux Kernel Version 6.2 Update rc4
Linux ≫ Linux Kernel Version 6.2 Update rc5
Linux ≫ Linux Kernel Version 6.2 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.192
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://git.kernel.org/stable/c/b591abac78e25269b12e3d7170c99463f8c5cb02
Patch
https://git.kernel.org/stable/c/e3ebc3e23bd9028a8a9a26cbc5985f99be445f65
Patch
https://git.kernel.org/stable/c/0769f997a7b6d5cb8336db0b4ec3d2d311b8097c
Patch
https://git.kernel.org/stable/c/7057a8f126f14f14b040faecfa220fd27c6c2f85
Patch