There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveausgdma.c in nouveausgdmacreatettm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20292.json"
[
{
"events": [
{
"introduced": "3.3"
},
{
"fixed": "4.9.298"
}
]
},
{
"events": [
{
"introduced": "4.10"
},
{
"fixed": "4.14.263"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.19.140"
}
]
},
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.4.59"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.7.16"
}
]
},
{
"events": [
{
"introduced": "5.8"
},
{
"fixed": "5.8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}
]