Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-47354

Опубликовано: 21 мая 2024
Источник: redhat
CVSS3: 6

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

Отчет

A flaw in the Linux kernel's DRM GPU scheduler (drm/sched): a job could be killed before all of its dependencies completed, allowing in-flight GPU operations to run against torn-down state and corrupt data. Triggering requires local access to submit GPU scheduler jobs, so Red Hat rates this Moderate (6.0), well below external scores (CVE.org 7.1; CISA 9.1, whose AV:N network vector is incorrect for a local-only GPU bug). Supported Red Hat Enterprise Linux streams are not affected; the RHEL 6 and RHEL 7 ELS kernels predate the DRM GPU scheduler framework, so the vulnerable code is not present.

Меры по смягчению последствий

No mitigation is required for Red Hat products: supported RHEL kernels are not affected, and the vulnerable DRM GPU scheduler code is not present in the RHEL 6/7 ELS kernels. In general, exploitation requires local access to submit GPU jobs; restricting access to DRM render/device nodes to trusted users limits exposure where the code is present.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2282399kernel: drm/sched: Avoid data corruptions

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

CVSS3: 7.1
nvd
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

CVSS3: 7.1
debian
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: d ...

CVSS3: 9.1
github
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

CVSS3: 9.1
fstec
больше 5 лет назад

Уязвимость функции drm_sched_entity_kill_jobs() ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

6 Medium

CVSS3