PT-2019-4502 · Linux+5 · Linux Kernel+5

罗权

·

Publicado

2018-04-06

·

Atualizado

2021-03-18

·

CVE-2020-7053

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.14 through 4.14.165 Linux kernel versions 4.19 through 4.19.96 Linux kernel versions 5.x before 5.2
Description The issue is related to a use-after-free in the i915 ppgtt close function in drivers/gpu/drm/i915/i915 gem gtt.c. This is connected to the i915 gem context destroy ioctl function in drivers/gpu/drm/i915/i915 gem context.c. The vulnerability can be exploited to cause a denial of service using the Intel i915 graphics driver system call.
Recommendations For Linux kernel versions 4.14 through 4.14.165, update to a version after 4.14.165 to resolve the issue. For Linux kernel versions 4.19 through 4.19.96, update to a version after 4.19.96 to resolve the issue. For Linux kernel versions 5.x before 5.2, update to version 5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the i915 gem context destroy ioctl system call to minimize the risk of exploitation.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1557
ALT-PU-2019-1139
ALT-PU-2019-1363
ALT-PU-2019-2321
ALT-PU-2019-2339
ALT-PU-2019-2488
ALT-PU-2019-2746
ALT-PU-2020-1069
ALT-PU-2020-1078
ALT-PU-2020-1189
ALT-PU-2020-2410
ALT-PU-2020-2433
BDU:2020-00361
CESA-2020_1567
CESA-2020_1769
CESA-2021_0856
CVE-2020-7053
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
RHSA-2020:1567
RHSA-2020:1769
RHSA-2020_1567
RHSA-2020_1769
RHSA-2021:0856
RHSA-2021:0857
RHSA-2021_0856
RHSA-2021_0857
SUSE-SU-2020:0511-1
SUSE-SU-2020:0558-1
SUSE-SU-2020:0559-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0580-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0605-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1663-1
SUSE-SU-2020_1663-1
USN-4255-1
USN-4255-2
USN-4285-1
USN-4287-1
USN-4287-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu