PT-2024-21630 · Linux+7 · Linux Kernel+7

Dave Airlie

·

Published

2024-02-28

·

Updated

2026-04-20

·

CVE-2024-27062

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0-rc6+
Description The vulnerability is related to the nouveau driver in the Linux kernel. It appears that the client object tree has no locking, which can cause races around adding or removing client objects, mostly related to vram bar mappings. This can lead to a general protection fault. The issue is resolved by locking the client object tree.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the vulnerability. Specifically, update to a version later than 6.8.0-rc6+. As a temporary workaround, consider disabling the nvkm object search function until a patch is available. Restrict access to the vulnerable module nouveau to minimize the risk of exploitation. Avoid using the nvif object map handle and nouveau ttm io mem reserve functions in the affected API endpoints until the issue is resolved.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-59631
BDU:2025-03086
CESA-2024_8856
CESA-2024_8870
CVE-2024-27062
ECHO-3653-5AF3-0DCF
INFSA-2024_8856
INFSA-2024_8870
INFSA-2024_9315
OESA-2024-1677
OESA-2024-1678
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
RHSA-2024:10942
RHSA-2024:5066
RHSA-2024:5067
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024:9315
RHSA-2024_8856
RHSA-2024_8870
RHSA-2024_9315
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:1644-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1

Affected Products

Almalinux
Centos
Debian
Linux Kernel
Red Hat
Rocky Linux
Suse
Nouveau