Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-44982

5.5 · MEDIUM
Published Sep 4, 2024 linux CWE-459 EPSS 0.24% (15th pctl)

Overview

CVE-2024-44982 is a medium-severity vulnerability affecting linux linux_kernel. It was published on September 4, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails

If the dpu_format_populate_layout() fails, then FB is prepared, but not

cleaned up. This ends up leaking the pin_count on the GEM object and

causes a splat during DRM file closure:

msm_obj->pin_count

WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc

[...]

Call trace:

update_lru_locked+0xc4/0xcc

put_pages+0xac/0x100

msm_gem_free_object+0x138/0x180

drm_gem_object_free+0x1c/0x30

drm_gem_object_handle_put_unlocked+0x108/0x10c

drm_gem_object_release_handle+0x58/0x70

idr_for_each+0x68/0xec

drm_gem_release+0x28/0x40

drm_file_free+0x174/0x234

drm_release+0xb0/0x160

__fput+0xc0/0x2c8

__fput_sync+0x50/0x5c

__arm64_sys_close+0x38/0x7c

invoke_syscall+0x48/0x118

el0_svc_common.constprop.0+0x40/0xe0

do_el0_svc+0x1c/0x28

el0_svc+0x4c/0x120

el0t_64_sync_handler+0x100/0x12c

el0t_64_sync+0x190/0x194

irq event stamp:

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.19, < 5.15.166 Affected

Frequently Asked Questions

What is CVE-2024-44982?

CVE-2024-44982 is a medium-severity vulnerability affecting linux linux_kernel. It was published on September 4, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2024-44982?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-44982?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-44982?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-44982 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.