Back

HIGH

drm/virtio: Fix GEM handle creation UAF

Published Aug 21, 2024

Description

Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done *after* we are done dereferencing the object.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 21, 2024
Updated Aug 5, 2026
Reserved Aug 21, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Aug 21, 2024