Linux kernel IOMMU GPU buffer unmap causes memory corruption
CVE-2024-21471 Published on May 6, 2024

Use After Free in Graphics Linux
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

NVD

Vulnerability Analysis

CVE-2024-21471 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2024-21471 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2024-21471

stack.watch emails you whenever new vulnerabilities are published in Google Android or Linux Kernel. Just hit a watch button to start following.

 
 

Affected Versions

Qualcomm, Inc. Snapdragon: qualcomm ar8035_firmware: qualcomm c-v2x_9150_firmware: qualcomm csra6640_firmware: qualcomm fastconnect_6200_firmware: qualcomm fastconnect_6800_firmware: qualcomm fastconnect_6900_firmware: qualcomm flight_rb5_5g_platform_firmware: qualcomm mdm9250_firmware: qualcomm mdm9650_firmware: qualcomm qam8255p_firmware: qualcomm qam8775p_firmware: qualcomm qamsrv1h_firmware: qualcomm qca6174a_firmware: qualcomm qca6310_firmware: qualcomm qca6335_firmware: qualcomm qca6391_firmware: qualcomm qca6436_firmware: qualcomm qca6564a_firmware: qualcomm qca6574_firmware: qualcomm qca6574a_firmware: qualcomm qca6595_firmware: qualcomm qca6595au_firmware: qualcomm qca6696_firmware: qualcomm qca6698aq_firmware: qualcomm qca8081_firmware: qualcomm qca8337_firmware: qualcomm qcm4325_firmware: qualcomm qcm4490_firmware: qualcomm qcm6125_firmware: qualcomm qcm6490_firmware: qualcomm qcn6024_firmware: qualcomm qcn9011_firmware: qualcomm qcn9024_firmware: qualcomm qcs410_firmware: qualcomm qcs5430_firmware: qualcomm qcs610_firmware: qualcomm qcs6125_firmware: qualcomm qcs6490_firmware: qualcomm qcs7230_firmware: qualcomm qcs8250_firmware: qualcomm qcs8550_firmware: qualcomm qrb5165n_firmware: qualcomm qsm8350_firmware: qualcomm_215_mobile_platform_firmware: qualcomm_video_collaboration_vc1_platform_firmware: qualcomm_video_collaboration_vc5_platform_firmware: qualcomm robotics_rb5_platform_firmware: qualcomm sa4150p_firmware: qualcomm sa6145p_firmware: qualcomm sa6150p_firmware: qualcomm csra6620_firmware: qualcomm fastconnect_6700_firmware: qualcomm fastconnect_7800_firmware: qualcomm mdm9628_firmware: qualcomm qam8295p_firmware: qualcomm qam8650p_firmware: qualcomm qamsrv1m_firmware: qualcomm qca6320_firmware: qualcomm qca6426_firmware: qualcomm qca6564au_firmware: qualcomm qca6574au_firmware: qualcomm qca6678aq_firmware: qualcomm qca6797aq_firmware: qualcomm qca9377_firmware: qualcomm qcm5430_firmware: qualcomm qcm8550_firmware: qualcomm qcn9012_firmware: qualcomm qcs4490_firmware: qualcomm qrb5165m_firmware: qualcomm_205_mobile_platform_firmware: qualcomm_video_collaboration_vc3_platform_firmware: qualcomm robotics_rb3_platform_firmware: qualcomm sa4155p_firmware: qualcomm sa6155p_firmware:

Exploit Probability

EPSS
0.11%
Percentile
29.62%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.