PT-2024-32237 · Linux · Linux Kernel

Boris Brezillon

+1

·

Published

2024-09-03

·

Updated

2024-10-09

·

CVE-2024-46837

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the drm/panthor component, where high priorities on group create were not properly restricted. This allowed any users to create a high priority group without permission checks, potentially leading to denial of service. The fix now only allows the DRM master or users with the CAP SYS NICE capability to set higher priorities than PANTHOR GROUP PRIORITY MEDIUM.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-05934
CVE-2024-46837

Affected Products

Linux Kernel