{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-46866",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-09-11T15:12:18.294Z",
        "datePublished": "2024-09-27T12:42:54.381Z",
        "dateUpdated": "2026-08-05T11:39:08.572Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:39:08.572Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: add missing bo locking in show_meminfo()\n\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\nhowever this state can change at any point leading to stuff like NPD and\nUAF, if the bo lock is not held. Grab the bo lock when calling\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\nobject_idr we now also need to hold a ref.\n\nv2 (MattB)\n  - Also add xe_bo_assert_held()\n\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Exploitation requires opening a local Xe DRM render node (`/dev/dri/renderD128`), issuing GEM/VM/exec ioctls, and reading `/proc/<pid>/fdinfo/<fd>`; there is no remote or adjacent-network path to `show_meminfo()`.\nAC:L - The attacker owns both sides of the race inside a single process — one thread loops on its own fdinfo while another loops BO validation/migration ioctls that drive `ttm_bo_move_null()`/`ttm_bo_tt_destroy()`; no condition lies outside attacker control and the SYSTEM↔TT move window is hit constantly on integrated Xe GPUs.\nPR:L - Only an unprivileged local account with normal GPU access is needed — the Xe driver sets DRIVER_RENDER, so the render node requires no DRM master or capability, and reading one's own `/proc/self/fdinfo` trivially satisfies PTRACE_MODE_READ.\nUI:N - The attacking process opens the device, creates the BOs, and reads its own fdinfo entirely on its own; no victim action or interaction with another user is required.\nS:U - The corruption and its effects stay within the kernel of the same machine, with no crossing of a hypervisor, IOMMU, or other security-authority boundary.\nC:H - The race yields use-after-free reads of freed `ttm_resource` and `ttm_tt` slab objects, and the values read (`res->mem_type`, `tt->page_flags`) directly steer the accounting numbers printed back to userspace in fdinfo, leaking freed-heap contents; per kernel guidance a UAF is scored High.\nI:H - The commit explicitly identifies a use-after-free, which is scored High because a freed-object race on repeatedly reallocated TTM slab objects can be groomed into memory-corruption/control primitives, and the stale `mem_type` selects the accumulator slot updated with the attacker-chosen BO size.\nA:H - `resource_is_vram()` dereferences `bo->ttm.resource` unconditionally, so hitting the `ttm_resource_free()` NULL window produces an immediate kernel oops, and the UAF reads add further crash paths — all repeatable at will by an unprivileged local user."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_drm_client.c"
                    ],
                    "versions": [
                        {
                            "version": "0845233388f8a26d00acf9bf230cfd4f36aa4c30",
                            "lessThan": "abc8feacacf8fae10eecf6fea7865e8c1fee419c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0845233388f8a26d00acf9bf230cfd4f36aa4c30",
                            "lessThan": "94c4aa266111262c96c98f822d1bccc494786fee",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_drm_client.c"
                    ],
                    "versions": [
                        {
                            "version": "6.8",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.8",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10.11",
                            "lessThanOrEqual": "6.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.10.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.11"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/abc8feacacf8fae10eecf6fea7865e8c1fee419c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/94c4aa266111262c96c98f822d1bccc494786fee"
                }
            ],
            "title": "drm/xe/client: add missing bo locking in show_meminfo()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-09-29T13:40:49.646755Z",
                                "id": "CVE-2024-46866",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-29T13:41:44.644Z"
                }
            }
        ]
    }
}