CVE-2024-44980
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/09/2024
Last modified:
10/10/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/xe: Fix opregion leak<br />
<br />
Being part o the display, ideally the setup and cleanup would be done by<br />
display itself. However this is a bigger refactor that needs to be done<br />
on both i915 and xe. For now, just fix the leak:<br />
<br />
unreferenced object 0xffff8881a0300008 (size 192):<br />
comm "modprobe", pid 4354, jiffies 4295647021<br />
hex dump (first 32 bytes):<br />
00 00 87 27 81 88 ff ff 18 80 9b 00 00 c9 ff ff ...&#39;............<br />
18 81 9b 00 00 c9 ff ff 00 00 00 00 00 00 00 00 ................<br />
backtrace (crc 99260e31):<br />
[] kmemleak_alloc+0x4b/0x80<br />
[] kmalloc_trace_noprof+0x312/0x3d0<br />
[] intel_opregion_setup+0x89/0x700 [xe]<br />
[] xe_display_init_noirq+0x2f/0x90 [xe]<br />
[] xe_device_probe+0x7a3/0xbf0 [xe]<br />
[] xe_pci_probe+0x333/0x5b0 [xe]<br />
[] local_pci_probe+0x48/0xb0<br />
[] pci_device_probe+0xc8/0x280<br />
[] really_probe+0xf8/0x390<br />
[] __driver_probe_device+0x8a/0x170<br />
[] driver_probe_device+0x23/0xb0<br />
[] __driver_attach+0xc7/0x190<br />
[] bus_for_each_dev+0x7d/0xd0<br />
[] driver_attach+0x1e/0x30<br />
[] bus_add_driver+0x117/0x250<br />
<br />
(cherry picked from commit 6f4e43a2f771b737d991142ec4f6d4b7ff31fbb4)
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.8 (including) | 6.10.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.11:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.11:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.11:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



