Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-43867— drm/nouveau: prime: fix refcount underflow

AI Predicted 5.5 Difficulty: Moderate EPSS 0.22% · P12

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinuxab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< 3bcb8bba72ce89667fa863054956267c450c47efaffected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< 906372e753c5027a1dc88743843b6aa2ad1aaecfaffected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< 16998763c62bb465ebc409d0373b9cdcef1a61a6affected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< ebebba4d357b6c67f96776a48ddbaf0060fa4c10affected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< f23cd66933fe76b84d8e282e5606b4d99068c320affected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< 2a1b327d57a8ac080977633a18999f032d7e9e3faffected
ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6< a9bf3efc33f1fbf88787a277f7349459283c9b95affected
3.9affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-43867

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/nouveau: prime: fix refcount underflow
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: prime: fix refcount underflow Calling nouveau_bo_ref() on a nouveau_bo without initializing it (and hence the backing ttm_bo) leads to a refcount underflow. Instead of calling nouveau_bo_ref() in the unwind path of drm_gem_object_init(), clean things up manually. (cherry picked from commit 1b93f3e89d03cfc576636e195466a0d728ad8de5)
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在未初始化nouveau_bo的情况下调用nouveau_bo_ref函数会导致引用计数下溢。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux ab9ccb96a6e6f95bcde6b8b2a524370efdbfdcd6 ~ 3bcb8bba72ce89667fa863054956267c450c47ef -
LinuxLinux 3.9 -

II. Public POCs for CVE-2024-43867

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-43867

登录查看更多情报信息。

Other References for CVE-2024-43867 (6)

Same Patch Batch · Linux · 2024-08-20 · 8 CVEs total

CVE-2024-438649.8 CRITICALnet/mlx5e: Fix CT entry update leaks of modify header context
CVE-2024-43861net: usb: qmi_wwan: fix memory leak for not ip packets
CVE-2024-43862net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlock to a mutex
CVE-2024-43863drm/vmwgfx: Fix a deadlock in dma buf fence polling
CVE-2024-43865s390/fpu: Re-add exception handling in load_fpu_state()
CVE-2024-43866net/mlx5: Always drain health in shutdown callback
CVE-2024-43868riscv/purgatory: align riscv_kernel_entry

IV. Related Vulnerabilities

V. Comments for CVE-2024-43867

No comments yet


Leave a comment