Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/i915/gem): The size of a partial GEM mapping is computed without accounting for the
Impact
The size of a partial GEM mapping is computed without accounting for the mapping offset, so the mapped window can extend past the end of the buffer object. A tenant that faults those pages reaches memory outside its own BO - read and write access to pages the driver never intended to expose to it.
Who can reach it
Tenant container holding /dev/dri/renderD* on an Intel i915 device: create a BO, request an mmap offset with a partial view / non-zero framebuffer offset, mmap it and touch pages past the object's end. Unprivileged, no display or master access required.
What to do
Update to a stable kernel carrying the fix (commits below; no fixed_in published in the record). Interim: drop /dev/dri/renderD* from containers running untrusted code on i915 nodes.
References
Related entries
- Linux kernel (drivers/gpu/drm/i915/gem): The access handler for a memory-mapped GEM object never bounds-checks theCVE-2022-49261 · Linux kernel (drivers/gpu/drm/i915/gem)High
- QEMU (qemu-img): `qemu-img info` on an untrusted qcow2 image reaches arbitrary host file read/writeCVE-2024-4467 · QEMU (qemu-img)High
- Linux kernel (drivers/gpu/drm/xe): Freeing a scheduler job dereferences the VM it belongs to, but the final exec-queueCVE-2024-44978 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery path runs without the state lock, soCVE-2024-45019 · Linux kernel mlx5_core TX timeout devlink health reporterHigh
- Arm Mali GPU kernel driver: Use-after-free in the Bifrost/Valhall GPU kernel driverCVE-2024-4610 · Arm Mali GPU kernel driverHigh
- Linux kernel (drivers/gpu/drm/xe): The preempt-fence lock lives inside the exec queue, but the queue reference isCVE-2024-46683 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.