PT-2024-5940 · Linux+2 · Linux Kernel+2

Published

2024-08-21

·

Updated

2025-01-09

·

CVE-2024-44979

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a missing workqueue destroy in the xe gt pagefault function of the Linux kernel's drm/xe component. On driver reload, the memory for the pagefault and access counter workqueues is not freed up. This can lead to a denial of service. The vulnerability exists due to insufficient input validation in the devm add action or reset function of the mgag200 component of the Linux kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06747
CVE-2024-44979
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu