{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-36018","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T13:50:33.155Z","datePublished":"2024-05-30T14:59:42.091Z","dateUpdated":"2026-08-05T11:31:38.174Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:31:38.174Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/uvmm: fix addr/range calcs for remap operations\n\ndEQP-VK.sparse_resources.image_rebind.2d_array.r64i.128_128_8\nwas causing a remap operation like the below.\n\nop_remap: prev: 0000003fffed0000 00000000000f0000 00000000a5abd18a 0000000000000000\nop_remap: next:\nop_remap: unmap: 0000003fffed0000 0000000000100000 0\nop_map: map: 0000003ffffc0000 0000000000010000 000000005b1ba33c 00000000000e0000\n\nThis was resulting in an unmap operation from 0x3fffed0000+0xf0000, 0x100000\nwhich was corrupting the pagetables and oopsing the kernel.\n\nFixes the prev + unmap range calcs to use start/end and map back to addr/range."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Triggered through the DRM_IOCTL_NOUVEAU_VM_BIND ioctl on a nouveau DRM device node; no network or remote reachability is involved.\nAC:L - The attacker fully controls the VA layout that produces a prev-only remap (map a range, then map over its tail), making the overshoot amount and target address deterministic; it reproduces from a stock Vulkan CTS test with no race or unknown state.\nPR:L - The ioctl is registered DRM_RENDER_ALLOW, so it works on an unauthenticated render node (/dev/dri/renderD*), which unprivileged desktop users hold via logind ACLs or the render group and which is routinely exposed to containers and GPU sandboxes.\nUI:N - The attacking process performs VM_INIT and VM_BIND entirely on its own file descriptor; no victim action or interaction is required.\nS:U - The corrupted GPU page tables and the resulting memory access are managed by the same kernel security authority; there is no VM, IOMMU, or hypervisor boundary crossed.\nC:H - Because the over-long unmap is silently dropped with -EINVAL when it crosses the managed-range boundary while cleanup still drops the BO reference, the GPU retains valid mappings on freed pages that get recycled to other processes and the kernel, giving the attacker's shaders an arbitrary read primitive.\nI:H - The bug performs an attacker-sized, attacker-placed PTE clear outside the intended range, corrupting live GPU page-table entries behind drm_gpuvm's bookkeeping, and the stale-mapping case leaves writable GPU DMA access to reallocated kernel memory.\nA:H - The reported symptom is a kernel oops — nvkm_vmm_iter() omits the NVKM_VMM_PDE_INVALID check on the unmap path, so walking into an unbacked or sparse PDE dereferences NULL or ERR_PTR(-EBUSY), and an unprivileged process can trigger it at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/nouveau/nouveau_uvmm.c"],"versions":[{"version":"b88baab828713ce0b49b185444b2ee83bed373a8","lessThan":"692a51bebf4552bdf0a79ccd68d291182a26a569","status":"affected","versionType":"git"},{"version":"b88baab828713ce0b49b185444b2ee83bed373a8","lessThan":"0c16020d2b69a602c8ae6a1dd2aac9a3023249d6","status":"affected","versionType":"git"},{"version":"b88baab828713ce0b49b185444b2ee83bed373a8","lessThan":"be141849ec00ef39935bf169c0f194ac70bf85ce","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/nouveau/nouveau_uvmm.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.26","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.5","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.26"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.8.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/692a51bebf4552bdf0a79ccd68d291182a26a569"},{"url":"https://git.kernel.org/stable/c/0c16020d2b69a602c8ae6a1dd2aac9a3023249d6"},{"url":"https://git.kernel.org/stable/c/be141849ec00ef39935bf169c0f194ac70bf85ce"}],"title":"nouveau/uvmm: fix addr/range calcs for remap operations","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-06T18:34:51.763969Z","id":"CVE-2024-36018","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-06T18:35:02.091Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:30:12.600Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/692a51bebf4552bdf0a79ccd68d291182a26a569","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0c16020d2b69a602c8ae6a1dd2aac9a3023249d6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/be141849ec00ef39935bf169c0f194ac70bf85ce","tags":["x_transferred"]}]}]}}