Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/nouveau/nvkm/core): Nouveau's per-client object tree had no locking at all, so concurrent
Impact
Nouveau's per-client object tree had no locking at all, so concurrent object creation and destruction - most visibly VRAM BAR mappings - corrupts the tree. The reported crash is a general protection fault on a wild pointer during object lookup, which is the signature of an attacker-influenceable dangling pointer in the object namespace that backs GPU memory mappings.
Who can reach it
An unprivileged multi-threaded process in a container holding /dev/dri/renderD* on a nouveau-driven GPU races object allocation against object free; the crash was reproduced by a plain Vulkan conformance run, so no exotic ioctl sequence is needed. Conditional on the open nouveau driver being the one bound to the GPU.
What to do
Update to a kernel with the fix commits below, which adds locking around the client object tree. Interim: blacklist nouveau where the proprietary NVIDIA driver is used, and otherwise keep /dev/dri away from untrusted tenants.
References
Related entries
- Linux kernel (drivers/gpu/drm/nouveau): Nouveau's VM_BIND remap path miscalculates the address and range of the unmapCVE-2024-36018 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel (net routing): Use-after-free in network route management (__dst_negative_advice) - actively exploitedCVE-2024-36971 · Linux kernel (net routing)High
- Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wildCVE-2024-38080 · Microsoft Hyper-VHigh
- Linux kernel (drivers/gpu/drm): DRM core stores a pointer to the caller's struct pid before taking a reference on itCVE-2024-39486 · Linux kernel (drivers/gpu/drm)High
- Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the userCVE-2024-40990 · Linux kernel mlx5_ib (shared receive queue)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2024-41011 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.