CVE-2022-49963

Source
https://cve.org/CVERecord?id=CVE-2022-49963
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49963.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49963
Downstream
Related
Published
2025-06-18T11:00:24Z
Modified
2026-08-12T03:51:43Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/i915/ttm: fix CCS handling
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/i915/ttm: fix CCS handling

Crucible + recent Mesa seems to sometimes hit:

GEM_BUG_ON(num_ccs_blks > NUM_CCS_BLKS_PER_XFER)

And it looks like we can also trigger this with gem_lmem_swapping, if we modify the test to use slightly larger object sizes.

Looking closer it looks like we have the following issues in migrate_copy():

  • We are using plain integer in various places, which we can easily overflow with a large object.

  • We pass the entire object size (when the src is lmem) into emit_pte() and then try to copy it, which doesn't work, since we only have a few fixed sized windows in which to map the pages and perform the copy. With an object > 8M we therefore aren't properly copying the pages. And then with an object > 64M we trigger the GEM_BUG_ON(num_ccs_blks > NUM_CCS_BLKS_PER_XFER).

So it looks like our copy handling for any object > 8M (which is our CHUNK_SZ) is currently broken on DG2.

Testcase: igt@gem_lmem_swapping (cherry picked from commit 8676145eb2f53a9940ff70910caf0125bd8a4bc2)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49963.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
da0595ae91da837929a00470ab40546090e5b9ae
Fixed
97434cb55bd884bd268626ec41489f79b261b2d4
Fixed
8d905254162965c8e6be697d82c7dbf5d08f574d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49963.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
5.19.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49963.json"