In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Fix potential bit_17 double-free
A userspace with multiple threads racing I915GEMSETTILING to set the tiling to I915TILINGNONE could trigger a double free of the bit17 bitmask. (Or conversely leak memory on the transition to tiled.) Move allocation/free'ing of the bitmask within the section protected by the obj lock.
[tursulin: Correct fixes tag and added cc stable.] (cherry picked from commit 10e0cbaaf1104f449d695c80bcacf930dcd3c42e)
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b591abac78e25269b12e3d7170c99463f8c5cb02",
"id": "CVE-2023-52930-17958080",
"digest": {
"function_hash": "218200855184547107307939583985603610338",
"length": 1656.0
},
"target": {
"function": "i915_gem_object_set_tiling",
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b591abac78e25269b12e3d7170c99463f8c5cb02",
"id": "CVE-2023-52930-347b1e45",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152782177599644362849969435492283479155",
"91540563807785863963584607598570157646",
"116251455662324835582442611867159844",
"209483577786531033324425253535699689577",
"325210690208965000065076218734075623266",
"61332014405039040550309407559714024769",
"224889384169666688594229049041036984149",
"275635292406797897423229644790674579189"
]
},
"target": {
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7057a8f126f14f14b040faecfa220fd27c6c2f85",
"id": "CVE-2023-52930-49e348d4",
"digest": {
"function_hash": "165371721595553718098798577082008378080",
"length": 1565.0
},
"target": {
"function": "i915_gem_object_set_tiling",
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0769f997a7b6d5cb8336db0b4ec3d2d311b8097c",
"id": "CVE-2023-52930-8906930c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152782177599644362849969435492283479155",
"91540563807785863963584607598570157646",
"116251455662324835582442611867159844",
"209483577786531033324425253535699689577",
"325210690208965000065076218734075623266",
"61332014405039040550309407559714024769",
"224889384169666688594229049041036984149",
"275635292406797897423229644790674579189"
]
},
"target": {
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7057a8f126f14f14b040faecfa220fd27c6c2f85",
"id": "CVE-2023-52930-a1386f49",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152782177599644362849969435492283479155",
"91540563807785863963584607598570157646",
"116251455662324835582442611867159844",
"209483577786531033324425253535699689577",
"325210690208965000065076218734075623266",
"61332014405039040550309407559714024769",
"224889384169666688594229049041036984149",
"275635292406797897423229644790674579189"
]
},
"target": {
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e3ebc3e23bd9028a8a9a26cbc5985f99be445f65",
"id": "CVE-2023-52930-adc3c595",
"digest": {
"function_hash": "96953418715243947946175550790497868011",
"length": 1557.0
},
"target": {
"function": "i915_gem_object_set_tiling",
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e3ebc3e23bd9028a8a9a26cbc5985f99be445f65",
"id": "CVE-2023-52930-c2148f29",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152782177599644362849969435492283479155",
"91540563807785863963584607598570157646",
"116251455662324835582442611867159844",
"209483577786531033324425253535699689577",
"325210690208965000065076218734075623266",
"61332014405039040550309407559714024769",
"224889384169666688594229049041036984149",
"275635292406797897423229644790674579189"
]
},
"target": {
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0769f997a7b6d5cb8336db0b4ec3d2d311b8097c",
"id": "CVE-2023-52930-eb1c7652",
"digest": {
"function_hash": "165371721595553718098798577082008378080",
"length": 1565.0
},
"target": {
"function": "i915_gem_object_set_tiling",
"file": "drivers/gpu/drm/i915/gem/i915_gem_tiling.c"
},
"signature_type": "Function",
"signature_version": "v1"
}
]