Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-44967— drm/mgag200: Bind I2C lifetime to DRM device

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于drm/mgag200组件的I2C设备存在生命周期管理不当。

CVSS 7.8 · High EPSS 0.22% · P13

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux b279df242972ae816a75cf1cc732af836f999100< 55a6916db77102765b22855d3a0add4751988b7c affected
b279df242972ae816a75cf1cc732af836f999100< 81d34df843620e902dd04aa9205c875833d61c17 affected
b279df242972ae816a75cf1cc732af836f999100< 9d96b91e03cba9dfcb4ac370c93af4dbc47d5191 affected
b279df242972ae816a75cf1cc732af836f999100< eb1ae34e48a09b7a1179c579aed042b032e408f4 affected
6.0 affected
< 6.0 unaffected
6.1.105≤ 6.1.* unaffected
6.6.46≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-44967

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/mgag200: Bind I2C lifetime to DRM device
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/mgag200: Bind I2C lifetime to DRM device Managed cleanup with devm_add_action_or_reset() will release the I2C adapter when the underlying Linux device goes away. But the connector still refers to it, so this cleanup leaves behind a stale pointer in struct drm_connector.ddc. Bind the lifetime of the I2C adapter to the connector's lifetime by using DRM's managed release. When the DRM device goes away (after the Linux device) DRM will first clean up the connector and then clean up the I2C adapter.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于drm/mgag200组件的I2C设备存在生命周期管理不当。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b279df242972ae816a75cf1cc732af836f999100 ~ 55a6916db77102765b22855d3a0add4751988b7c -
Linux Linux 6.0 -

II. Public POCs for CVE-2024-44967

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-44967

登录查看更多情报信息。

Patches & Fixes for CVE-2024-44967 (1)

Same Patch Batch · Linux · 2024-09-04 · 58 CVEs total

CVE-2024-44984 10.0 CRITICAL bnxt_en: Fix double DMA unmapping for XDP_REDIRECT
CVE-2024-44985 9.8 CRITICAL ipv6: prevent possible UAF in ip6_xmit()
CVE-2024-44970 9.8 CRITICAL net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
CVE-2024-44998 9.8 CRITICAL atm: idt77252: prevent use after free in dequeue_rx()
CVE-2024-44988 8.8 HIGH net: dsa: mv88e6xxx: Fix out-of-bound access
CVE-2024-44994 8.8 HIGH iommu: Restore lost return in iommu_report_device_fault()
CVE-2024-44986 8.1 HIGH ipv6: fix possible UAF in ip6_finish_output2()
CVE-2024-44973 8.1 HIGH mm, slub: do not call do_slab_free for kfence object
CVE-2024-44987 7.8 HIGH ipv6: prevent UAF in ip6_send_skb()
CVE-2024-44951 7.8 HIGH serial: sc16is7xx: fix TX fifo corruption
CVE-2024-44949 7.8 HIGH parisc: fix a possible DMA corruption
CVE-2024-44959 7.8 HIGH tracefs: Use generic inode RCU for synchronizing freeing
CVE-2024-44954 7.8 HIGH ALSA: line6: Fix racy access to midibuf
CVE-2024-45000 7.8 HIGH fs/netfs/fscache_cookie: add missing "n_accesses" check
CVE-2024-44966 7.8 HIGH binfmt_flat: Fix corruption when not offsetting data start
CVE-2024-44974 7.8 HIGH mptcp: pm: avoid possible UaF when selecting endp
CVE-2024-44995 7.8 HIGH net: hns3: fix a deadlock problem when config TC during resetting
CVE-2024-44978 7.8 HIGH drm/xe: Free job before xe_exec_queue_put
CVE-2024-44997 7.8 HIGH net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb()
CVE-2024-44992 7.5 HIGH smb/client: avoid possible NULL dereference in cifs_free_subrequest()

Showing top 20 of 58 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-44967

No comments yet


Leave a comment