PT-2024-32237 · Linux · Linux Kernel
Boris Brezillon
+1
·
Published
2024-09-03
·
Updated
2024-10-09
·
CVE-2024-46837
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the drm/panthor component, where high priorities on group create were not properly restricted. This allowed any users to create a high priority group without permission checks, potentially leading to denial of service. The fix now only allows the DRM master or users with the CAP SYS NICE capability to set higher priorities than PANTHOR GROUP PRIORITY MEDIUM.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel