Linux kernel
cpe:2.3:o:kernel:linux_kernel:*:*:*:*:*:*:*
- >= 7.0.0-070000rc3, < 7.0.0-070000rc3-generic
A vulnerability in the Linux kernel's Direct Rendering Manager (DRM) for the XE graphics driver has been addressed. This issue involved improper management of virtual memory area (VMA) remapping during 3D workloads, which could lead to warnings about invalid or overlapping VMA insertions. The problem arose because the system failed to correctly track and manage the previous and next VMA bindings, especially when re-inserting VMAs that had been partially unbound. As a result, the virtual memory could end up in a corrupted state, potentially causing issues when other operations tried to interact with the affected memory range.
The vulnerability could disrupt the normal operation of the graphics driver, leading to warnings about VMA management and potentially causing instability in applications that rely on 3D graphics processing.
The vulnerability can be reproduced by performing 3D workloads using applications that interface with the Vulkan graphics API, such as those using the vkd3d Vulkan Direct3D 12 implementation. During these operations, the improper VMA remapping management can be observed, triggering warnings about the VMA handling.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the Linux kernel's official website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.