{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-50030",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-10-21T12:17:06.068Z",
        "datePublished": "2024-10-21T19:39:33.127Z",
        "dateUpdated": "2026-08-05T11:41:06.500Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:41:06.500Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/ct: prevent UAF in send_recv()\n\nEnsure we serialize with completion side to prevent UAF with fence going\nout of scope on the stack, since we have no clue if it will fire after\nthe timeout before we can erase from the xa. Also we have some dependent\nloads and stores for which we need the correct ordering, and we lack the\nneeded barriers. Fix this by grabbing the ct->lock after the wait, which\nis also held by the completion side.\n\nv2 (Badal):\n - Also print done after acquiring the lock and seeing timeout.\n\n(cherry picked from commit 52789ce35c55ccd30c4b67b9cc5b2af55e0122ea)"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable blocking CT round-trip is reached from the world-readable sysfs attributes under /sys/class/drm/cardN/device/tile0/gt0/freq0/ and from DRM render-node ioctls on /dev/dri/renderD128, both of which require local system access. There is no network-facing consumer of xe_guc_ct_send_recv().\nAC:L - The attacker controls both sides of the race: it starts the 1-second deadline by reading cur_freq, and it controls G2H/H2G response latency by flooding the CT queue (the driver itself notes a full 4KiB H2G buffer \"takes a little over a second to process\") or by hanging the GPU to force a reset, then retries indefinitely until the completion lands in the window.\nPR:L - The freq0/*_freq attributes are DEVICE_ATTR_RO (0444), readable by any unprivileged local user with no capabilities, and the xe render node (DRIVER_RENDER) is accessible to ordinary users for generating the CT load. No CAP_SYS_ADMIN or root is required anywhere on the path.\nUI:N - The attacker performs every step itself — reading the sysfs file and submitting GPU work to stall the CT queue. No victim action or cooperation is needed.\nS:U - The corruption is of kernel stack memory belonging to the same kernel security authority; there is no VM, IOMMU, or sandbox boundary crossed in the primary local attack path.\nC:H - The completion side reads response_buffer from the already-popped stack frame and memcpy()s the G2H payload through it, giving an attacker-influenced pointer write that can be steered to place kernel data where the attacker can read it back; the corrupted stack also exposes saved kernel state.\nI:H - This is a use-after-free write into a live kernel stack — the worker writes fail/error/hint/response_len/response_data/done into a reused frame and can memcpy up to GUC_CTB_HXG_MSG_MAX_LEN dwords through a stale, groomable pointer, yielding return-address overwrite and control-flow hijack leading to privilege escalation.\nA:H - Writing into a popped stack frame and dereferencing a stale response_buffer pointer reliably produces kernel stack corruption, oops or panic, and the trigger can be repeated at will by an unprivileged user."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_guc_ct.c"
                    ],
                    "versions": [
                        {
                            "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
                            "lessThan": "8ed7dd4c55e4fb21531a9645aeb66a30eaf43a46",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
                            "lessThan": "db7f92af626178ba59dbbcdd5dee9ec24a987a88",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_guc_ct.c"
                    ],
                    "versions": [
                        {
                            "version": "6.8",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.8",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.4",
                            "lessThanOrEqual": "6.11.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.11.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.12"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/8ed7dd4c55e4fb21531a9645aeb66a30eaf43a46"
                },
                {
                    "url": "https://git.kernel.org/stable/c/db7f92af626178ba59dbbcdd5dee9ec24a987a88"
                }
            ],
            "title": "drm/xe/ct: prevent UAF in send_recv()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-50030",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-10-22T13:26:12.362646Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-10-22T13:28:45.887Z"
                }
            }
        ]
    }
}