#VU91451 Improper locking in Linux kernel


Published: 2024-06-08

Vulnerability identifier: #VU91451

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48634

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the gma_crtc_page_flip() function in drivers/gpu/drm/gma500/gma_display.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/c5812807e416618477d1bb0049727ce8bb8292fd
http://git.kernel.org/stable/c/e5ae504c8623476e13032670f1a6d6344d53ec9b
http://git.kernel.org/stable/c/a6ed7624bf4d0a32f2631e74828bca7b7bf15afd
http://git.kernel.org/stable/c/63e37a79f7bd939314997e29c2f5a9f0ef184281


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability