{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-38581","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-06-18T19:36:34.927Z","datePublished":"2024-06-19T13:37:38.509Z","dateUpdated":"2026-08-05T11:32:57.888Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:32:57.888Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix use-after-free issue\n\nDelete fence fallback timer to fix the ramdom\nuse-after-free issue.\n\nv2: move to amdgpu_mes.c"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable path lives in the amdgpu GPU driver and is reached through local device access — opening/ioctl'ing /dev/dri/renderD* triggers pm_runtime_get_sync(), and the resulting runtime-PM resume runs amdgpu_mes_self_test(). There is no network-facing component.\nAC:L - The attacker drives both sides of the timer-versus-free race: they trigger the MES self-test arbitrarily often via runtime PM cycles, and they control GPU load so the IB test times out — the path on which the fallback timer is left deterministically armed across kfree(ring). Repeated attempts are free and unlimited.\nPR:L - A basic unprivileged local user with access to the DRM render node (default on desktop/laptop distros via the render group or logind ACLs) can open the device and force runtime suspend/resume cycles; no capabilities or root are needed.\nUI:N - The attacker self-triggers the runtime-PM resume that runs the self-test through its own open()/ioctl() calls; no victim action such as a manual suspend or file open is required.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed struct amdgpu_ring comes from a generic kmalloc cache reclaimable by attacker-sprayed data, and the timer callback dereferences ring->adev, ring->fence_drv.fences[] and fence->ops from it, allowing attacker-directed reads of arbitrary kernel memory.\nI:H - The callback performs atomic_cmpxchg() and RCU_INIT_POINTER() writes into the freed object and makes indirect calls through fence->ops read out of reclaimed memory, yielding write and control-flow-hijack primitives; freeing an armed timer_list also corrupts the timer base list.\nA:H - Even unweaponized, the fallback timer firing on freed memory produces a use-after-free oops/panic or timer-list corruption, and it can be re-triggered on every resume cycle."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c"],"versions":[{"version":"8c5e13ec6a2c26d31d0551dc382661dc10823be0","lessThan":"70b1bf6d9edc8692d241f59a65f073aec6d501de","status":"affected","versionType":"git"},{"version":"8c5e13ec6a2c26d31d0551dc382661dc10823be0","lessThan":"39cfce75168c11421d70b8c0c65f6133edccb82a","status":"affected","versionType":"git"},{"version":"8c5e13ec6a2c26d31d0551dc382661dc10823be0","lessThan":"0f98c144c15c8fc0f3176c994bd4e727ef718a5c","status":"affected","versionType":"git"},{"version":"8c5e13ec6a2c26d31d0551dc382661dc10823be0","lessThan":"948255282074d9367e01908b3f5dcf8c10fc9c3d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c"],"versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","status":"unaffected","versionType":"semver"},{"version":"6.1.93","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.33","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.12","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.1.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.6.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.8.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/70b1bf6d9edc8692d241f59a65f073aec6d501de"},{"url":"https://git.kernel.org/stable/c/39cfce75168c11421d70b8c0c65f6133edccb82a"},{"url":"https://git.kernel.org/stable/c/0f98c144c15c8fc0f3176c994bd4e727ef718a5c"},{"url":"https://git.kernel.org/stable/c/948255282074d9367e01908b3f5dcf8c10fc9c3d"}],"title":"drm/amdgpu/mes: fix use-after-free issue","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-20T14:58:15.450879Z","id":"CVE-2024-38581","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-20T14:58:23.883Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T04:12:25.835Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/70b1bf6d9edc8692d241f59a65f073aec6d501de","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/39cfce75168c11421d70b8c0c65f6133edccb82a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0f98c144c15c8fc0f3176c994bd4e727ef718a5c","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/948255282074d9367e01908b3f5dcf8c10fc9c3d","tags":["x_transferred"]}]}]}}