EN

Tracker / CVE-2022-50454

CVE-2022-50454

Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in nouveau_gem_prime_import_sg_table() nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code back to the caller. On failures, ttm will call nouveau_bo_del_ttm() and free the memory.Thus, when nouveau_bo_init() returns an error, the gem object has already been released. Then the call to nouveau_bo_ref() will use the freed "nvbo->bo" and lead to a use-after-free bug. We should delete the call to nouveau_bo_ref() to avoid the use-after-free.

Prodotti e versioni affette

linux linux_kernel · 5.11 → 5.15.75
linux linux_kernel · 5.16 → 5.19.17
linux linux_kernel · 5.4 → 5.4.220
linux linux_kernel · 5.5 → 5.10.150
linux linux_kernel · 6.0 → 6.0.3

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti