CVE-2024-46837

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Oct 9, 2024

Summary

CVE-2024-46837 is a vulnerability affecting the Linux kernel's drm/panthor component. This issue permitted any user to create high-priority groups without proper permissions checks, potentially leading to denial of service. The vulnerability has been mitigated by restricting the ability to set higher priorities to the DRM master or users with CAP_SYS_NICE capability. The checks for priority level validity are now performed at the ioctl level, reducing the risk. This change should not impact the sole user of the uAPI in Mesa, as its priority level is set to MEDIUM by default.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share