Описание
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
Отчет
A flaw in the Linux kernel's DRM GPU scheduler (drm/sched): a job could be killed before all of its dependencies completed, allowing in-flight GPU operations to run against torn-down state and corrupt data. Triggering requires local access to submit GPU scheduler jobs, so Red Hat rates this Moderate (6.0), well below external scores (CVE.org 7.1; CISA 9.1, whose AV:N network vector is incorrect for a local-only GPU bug). Supported Red Hat Enterprise Linux streams are not affected; the RHEL 6 and RHEL 7 ELS kernels predate the DRM GPU scheduler framework, so the vulnerable code is not present.
Меры по смягчению последствий
No mitigation is required for Red Hat products: supported RHEL kernels are not affected, and the vulnerable DRM GPU scheduler code is not present in the RHEL 6/7 ELS kernels. In general, exploitation requires local access to submit GPU jobs; restricting access to DRM render/device nodes to trusted users limits exposure where the code is present.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | ||
| Red Hat Enterprise Linux 9 | kernel | Not affected | ||
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected |
Показывать по
Дополнительная информация
Статус:
6 Medium
CVSS3
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
In the Linux kernel, the following vulnerability has been resolved: d ...
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
Уязвимость функции drm_sched_entity_kill_jobs() ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации
6 Medium
CVSS3