Executive brief
The Nouveau GPU driver in the Linux kernel contains a use-after-free vulnerability in its graphics memory handling code. When importing graphics memory from a shared buffer table fails, the code incorrectly attempts to release an already-freed memory object, which could lead to system crashes, memory corruption, or potential code execution on systems with Nvidia GPUs.
Technical details
This is a use-after-free vulnerability in the nouveau_gem_prime_import_sg_table() function within the Nouveau DRM driver. When nouveau_bo_init() fails, the underlying TTM (Translation Table Maps) library automatically calls nouveau_bo_del_ttm() to free the buffer object. The vulnerable code then calls nouveau_bo_ref(NULL, &nvbo) on the already-freed object, leading to a use-after-free condition. The attack vector requires local access to trigger the GPU driver code path via graphics operations, making it exploitable by unprivileged local users with GPU access. The fix simply removes the redundant nouveau_bo_ref() call. Patches are available in Linux kernel v5.4 and later.
Affected products
- Linux Linux kernel v5.4 through at least v6.8 (prior to patch commit 540dfd188ea2940582841c1c220bd035a7db0e51)
Timeline
- 2022-07-05: disclosed: Fix committed by Jianglei Nie
- 2022-07-07: patched: Upstream patch merged by Lyude Paul
- 2022-10-24: patched: Backported to Linux stable trees v5.4+
- 2025-10-01: advisory: CVE-2022-50454 published