Back

HIGH

drm/xe/vm: move xa_alloc to prevent UAF

Published Oct 21, 2024

Description

Evil user can guess the next id of the vm before the ioctl completes and then call vm destroy ioctl to trigger UAF since create ioctl is still referencing the same vm. Move the xa_alloc all the way to the end to prevent this.

v2: - Rebase

(cherry picked from commit dcfd3971327f3ee92765154baebbaece833d3ca9)

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Oct 21, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024