Executive brief
A vulnerability was identified in the Linux kernel's Direct Rendering Manager (DRM) subsystem, which handles communication between the operating system and graphics hardware. Due to improper synchronization, certain internal data structures could be accessed after they have been freed from memory. A local attacker could exploit this to cause a system crash or unpredictable behavior, impacting the stability and availability of the affected system.
Technical details
A race condition exists in the drm_client_modeset_probe function within drivers/gpu/drm/drm_client_modeset.c. The modes[] array contains pointers to connector mode lists that are protected by the dev->mode_config.mutex. However, the mutex was being unlocked before the modes[] array was finished being used, potentially allowing the memory pointed to by the array to be freed or reused. An attacker with local access could trigger this use-after-free condition to cause a kernel panic (denial of service). The fix involves moving the mutex_unlock call to after the modeset configuration is complete.
Affected products
- Linux Linux Kernel versions up to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7, 6.9-rc1 to 6.9-rc3
Timeline
- 2024-04-04: other: Vulnerability fixed in source code
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/04e018bd913d3d3336ab7d21c2ad31a9175fe984
- https://git.kernel.org/stable/c/18c8cc6680ce938d0458859b6a08b4d34f7d8055
- https://git.kernel.org/stable/c/3eadd887dbac1df8f25f701e5d404d1b90fd0fea
- https://git.kernel.org/stable/c/41586487769eede64ab1aa6c65c74cbf76c12ef0
- https://git.kernel.org/stable/c/5a2f957e3c4553bbb100504a1acfeaeb33f4ca4e
- https://git.kernel.org/stable/c/8ceb873d816786a7c8058f50d903574aff8d3764
- https://git.kernel.org/stable/c/d2dc6600d4e3e1453e3b1fb233e9f97e2a1ae949