CVE-2024-46837
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-46837 is a vulnerability affecting the Linux kernel's drm/panthor component. This issue permitted any user to create high-priority groups without proper permissions checks, potentially leading to denial of service. The vulnerability has been mitigated by restricting the ability to set higher priorities to the DRM master or users with CAP_SYS_NICE capability. The checks for priority level validity are now performed at the ioctl level, reducing the risk. This change should not impact the sole user of the uAPI in Mesa, as its priority level is set to MEDIUM by default.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX