#VU94307 Resource management error in Linux kernel - CVE-2024-40987


Vulnerability identifier: #VU94307

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-40987

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the sumo_construct_vid_mapping_table() function in drivers/gpu/drm/amd/amdgpu/kv_dpm.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/4ad7d49059358ceadd352b4e2511425bdb68f400
https://git.kernel.org/stable/c/1c44f7759a5650acf8f13d3e0a184d09e03be9e4
https://git.kernel.org/stable/c/d8a04a6bfa75251ba7bcc3651ed211e82f13f388
https://git.kernel.org/stable/c/4d020c1dbd2b2304f44d003e6de956ae570049dc
https://git.kernel.org/stable/c/fc5cb952e6723c5c55e47b8cf94a891bd4af1a86
https://git.kernel.org/stable/c/b065d79ed06a0bb4377bc6dcc2ff0cb1f55a798f
https://git.kernel.org/stable/c/b0d612619ed70cab476c77b19e00d13aa414e14f
https://git.kernel.org/stable/c/f0d576f840153392d04b2d52cf3adab8f62e8cb6


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability