drm/virtio: Fix GEM handle creation UAF
Published Aug 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done *after* we are done dereferencing the object.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.4
- Version 4.19.270StatusunaffectedConstraints<=4.19.*
- Version 5.10.164StatusunaffectedConstraints<=5.10.*
- Version 5.15.89StatusunaffectedConstraints<=5.15.*
- Version 5.4.229StatusunaffectedConstraints<=5.4.*
- Version 6.1.7StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.4 · < 4.19.270
- ≥ 4.20 · < 5.4.229
- ≥ 5.5 · < 5.10.164
- ≥ 5.11 · < 5.15.89
- ≥ 5.16 · < 6.1.7
- 6.2
- 6.2
- 6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel
Will not fix
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-48899 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2306420 Issue Tracking
- https://git.kernel.org/stable/c/011ecdbcd520c90c344b872ca6b4821f7783b2f8 Patch
- https://git.kernel.org/stable/c/19ec87d06acfab2313ee82b2a689bf0c154e57ea Patch
- https://git.kernel.org/stable/c/52531258318ed59a2dc5a43df2eaf0eb1d65438e Patch
- https://git.kernel.org/stable/c/68bcd063857075d2f9edfed6024387ac377923e2 Patch
- https://git.kernel.org/stable/c/adc48e5e408afbb01d261bd303fd9fbbbaa3e317 Patch
- https://git.kernel.org/stable/c/d01d6d2b06c0d8390adf8f3ba08aa60b5642ef73 Patch
- https://lore.kernel.org/linux-cve-announce/2024082111-CVE-2022-48899-f3e8@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48899
- https://www.cve.org/CVERecord?id=CVE-2022-48899
Change history (0)
No recorded changes yet.