{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-46709","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-09-11T15:12:18.252Z","datePublished":"2024-09-13T06:33:41.392Z","dateUpdated":"2026-08-05T11:38:04.182Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:38:04.182Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix prime with external buffers\n\nMake sure that for external buffers mapping goes through the dma_buf\ninterface instead of trying to access pages directly.\n\nExternal buffers might not provide direct access to readable/writable\npages so to make sure the bo's created from external dma_bufs can be\nread dma_buf interface has to be used.\n\nFixes crashes in IGT's kms_prime with vgem. Regular desktop usage won't\ntrigger this due to the fact that virtual machines will not have\nmultiple GPUs but it enables better test coverage in IGT."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires opening the vmwgfx DRM device node and issuing local ioctls (PRIME_FD_TO_HANDLE, ADDFB2, atomic modeset/DIRTYFB/VMW_PRESENT_READBACK). There is no network-reachable path into drivers/gpu/drm/vmwgfx.\nAC:L - The attacker performs every step deterministically — create/export an external dma-buf, import it into vmwgfx, build a framebuffer, and trigger the CPU blit via a modeset or present-readback; there is no race or memory-layout condition outside the attacker's control.\nPR:L - Only local unprivileged access to /dev/dri/card0 is needed; PRIME import is DRM_RENDER_ALLOW (no auth), and DRM master is granted automatically to the first opener of a master-less node, which any seat/video-group user obtains without root.\nUI:N - The attacking process creates the external dma-buf, imports it, adds the framebuffer and drives the modeset itself. No action by another user or administrator is required.\nS:U - The invalid page mappings and memcpy corruption stay inside the guest kernel's own security authority; this is a guest DRM driver bug, not a hypervisor or IOMMU boundary crossing.\nC:H - vmw_bo_cpu_blit_line() kmap_atomic()s attacker-influenced, non-CPU-mappable page pointers derived from the imported sg table and memcpys from them into the display surface's buffer, which userspace can read back via VMW_PRESENT_READBACK — disclosing arbitrary kernel memory.\nI:H - In the readback direction the external bo is the memcpy destination, so attacker-controlled framebuffer bytes are written through those bogus page pointers into unrelated kernel memory, giving a kernel write primitive.\nA:H - The maintainer states the change \"fixes crashes in IGT's kms_prime with vgem\"; dereferencing invalid page pointers under kmap_atomic (preemption and page faults disabled) reliably oopses or panics the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/vmwgfx/vmwgfx_blit.c","drivers/gpu/drm/vmwgfx/vmwgfx_drv.h","drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c"],"versions":[{"version":"65674218b43f2dd54587ab2b06560e17c30d8b41","lessThan":"9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4","status":"affected","versionType":"git"},{"version":"b32233accefff1338806f064fb9b62cf5bc0609f","lessThan":"5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854","status":"affected","versionType":"git"},{"version":"b32233accefff1338806f064fb9b62cf5bc0609f","lessThan":"50f1199250912568606b3778dc56646c10cb7b04","status":"affected","versionType":"git"},{"version":"2cdb71c975a10b8774fcd199f16f9ea88948de50","status":"affected","versionType":"git"},{"version":"6.6.29","lessThan":"6.6.49","status":"affected","versionType":"semver"},{"version":"6.8.8","lessThan":"6.9","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/vmwgfx/vmwgfx_blit.c","drivers/gpu/drm/vmwgfx/vmwgfx_drv.h","drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.6.49","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.10.8","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.29","versionEndExcluding":"6.6.49"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.10.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9a9716bbbf3dd6b6cbefba3abcc89af8b72631f4"},{"url":"https://git.kernel.org/stable/c/5c12391ee1ab59cb2f3be3f1f5e6d0fc0c2dc854"},{"url":"https://git.kernel.org/stable/c/50f1199250912568606b3778dc56646c10cb7b04"}],"title":"drm/vmwgfx: Fix prime with external buffers","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-29T15:00:04.048988Z","id":"CVE-2024-46709","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-29T15:00:18.143Z"}}]}}