{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-50090",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-10-21T19:36:19.942Z",
        "datePublished": "2024-11-05T17:04:54.546Z",
        "dateUpdated": "2026-08-05T11:41:34.890Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:41:34.890Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix overflow in oa batch buffer\n\nBy default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch\nbuffer, this is not a problem if batch buffer is only used once but\noa reuses the batch buffer for the same metric and at each call\nit appends a MI_BATCH_BUFFER_END, printing the warning below and then\noverflowing.\n\n[  381.072016] ------------[ cut here ]------------\n[  381.072019] xe 0000:00:02.0: [drm] Assertion `bb->len * 4 + bb_prefetch(q->gt) <= size` failed!\n               platform: LUNARLAKE subplatform: 1\n               graphics: Xe2_LPG / Xe2_HPG 20.04 step B0\n               media: Xe2_LPM / Xe2_HPM 20.00 step B0\n               tile: 0 VRAM 0 B\n               GT: 0 type 1\n\nSo here checking if batch buffer already have MI_BATCH_BUFFER_END if\nnot append it.\n\nv2:\n- simply fix, suggestion from Ashutosh\n\n(cherry picked from commit 9ba0e0f30ca42a98af3689460063edfb6315718a)"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is reached through the xe DRM render node (`/dev/dri/renderD*`) via the OA stream open ioctl followed by `DRM_XE_OBSERVATION_IOCTL_CONFIG` on the returned fd. This requires local access to the GPU device node; there is no remote or adjacent-network path.\nAC:L - Triggering is fully deterministic — the attacker opens one OA stream and loops the CONFIG ioctl alternating between two metric sets, with `bb->len` incrementing by exactly one dword per call, so the overflow offset is precisely attacker-chosen and no race or unknown memory layout is involved. CONFIG_DRM_XE is the default driver for all modern Intel graphics (Meteor Lake, Lunar Lake, DG2/Arc, Battlemage) in distro kernels.\nPR:L - Only an unprivileged local account with render-node access and an exec queue is needed: the query-sampling path sets `privileged_op = false` (`xe_oa.c:1826`), bypassing the `perfmon_capable()` gate at stream open, and `xe_oa_ioctl()`/`xe_oa_config_locked()` perform no capability check at all. Render nodes are world-accessible or render-group accessible on common distros and reachable by ordinary apps on Android/ChromeOS.\nUI:N - The attacker performs the entire sequence — open stream, loop the config ioctl — within their own process. No victim action is required.\nS:U - The out-of-bounds write and its consequences are confined to kernel memory managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed by the flaw itself.\nC:H - The overflow writes into the shared 1 MB `kernel_bb_pool` holding live `xe_migrate` command streams; a stray MI_BATCH_BUFFER_END truncates a BO clear/copy batch, leaving stale memory contents exposed to another client, or corrupts a PTE-emitting batch so GPU page tables map arbitrary memory readable by attacker GPU work. On discrete GPUs the write lands in a `kvzalloc()`'d kernel heap buffer, giving OOB access to adjacent kernel objects.\nI:H - This is an unbounded out-of-bounds kernel write of a fixed dword (0x05000000) at an offset the attacker selects exactly by iteration count, hitting vmap'd BO pages on integrated GPUs and the kernel heap on discrete GPUs. It also rewrites GPU command streams that the engine executes with full GGTT access, making control-flow and page-table corruption achievable.\nA:H - The reported symptom is a driver assertion failure and buffer overflow; continued iteration corrupts in-flight kernel batch buffers causing GPU hangs and device wedging, and writing past the pool mapping produces a kernel oops/panic."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_bb.c"
                    ],
                    "versions": [
                        {
                            "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
                            "lessThan": "bcb5be3421705e682b0b32073ad627056d6bc2a2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "dd08ebf6c3525a7ea2186e636df064ea47281987",
                            "lessThan": "6c10ba06bb1b48acce6d4d9c1e33beb9954f1788",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/gpu/drm/xe/xe_bb.c"
                    ],
                    "versions": [
                        {
                            "version": "6.8",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.8",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.4",
                            "lessThanOrEqual": "6.11.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.11.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.8",
                                    "versionEndExcluding": "6.12"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/bcb5be3421705e682b0b32073ad627056d6bc2a2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6c10ba06bb1b48acce6d4d9c1e33beb9954f1788"
                }
            ],
            "title": "drm/xe/oa: Fix overflow in oa batch buffer",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-120",
                                "lang": "en",
                                "description": "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 5.5,
                            "attackVector": "LOCAL",
                            "baseSeverity": "MEDIUM",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                            "integrityImpact": "NONE",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "NONE"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-02-18T15:56:39.428028Z",
                                "id": "CVE-2024-50090",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-02-18T15:57:57.426Z"
                }
            }
        ]
    }
}