CVE-2024-26657

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 2, 2024
Updated: Jan 7, 2025
CWE ID 476

Summary

CVE-2024-26657 is a vulnerability affecting the Linux kernel that was recently resolved. This issue, reported by Joonkyo Jung, can be triggered by sending an amdgpu_cs_wait_ioctl to the AMDGPU DRM driver on specific ASICs with valid context. The bug exists in the drm_sched_entity_init function where a null pointer dereference occurs due to the logic change in commit 1decbf6bb0b4dc56c9da6c5e57b994ebfc2be3aa. As a result, the ioctl AMDGPU_WAIT_CS returns success even when there is no job, leading to a kernel NULL pointer dereference. The provided stack trace demonstrates the error condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share