SB20240531143 - Use-after-free in Linux kernel amd amdgpu driver
Published: May 31, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2021-47142)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the amdgpu_ttm_tt_unpopulate() function in drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0707c3fea8102d211631ba515ef2159707561b0d
- https://git.kernel.org/stable/c/3293cf3513d69f00c14d43e2020826d45ea0e46a
- https://git.kernel.org/stable/c/952ab3f9f48eb0e8050596d41951cf516be6b122
- https://git.kernel.org/stable/c/a849e218556f932576c0fb1c5a88714b61709a17
- https://git.kernel.org/stable/c/7398c2aab4da960761ec182d04d6d5abbb4a226e
- https://git.kernel.org/stable/c/f98cdf084405333ee2f5be548a91b2d168e49276
- https://git.kernel.org/stable/c/d4ea141fd4b40636a8326df5a377d9c5cf9b3faa
- https://git.kernel.org/stable/c/1e5c37385097c35911b0f8a0c67ffd10ee1af9a2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.235
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.193
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.271
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.271
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.124