CVE-2024-36960

Source
https://cve.org/CVERecord?id=CVE-2024-36960
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36960.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-36960
Downstream
Related
Published
2024-06-03T07:49:58.951Z
Modified
2026-03-14T12:34:17.182658Z
Summary
drm/vmwgfx: Fix invalid reads in fence signaled events
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: Fix invalid reads in fence signaled events

Correctly set the length of the drm_event to the size of the structure that's actually used.

The length of the drmevent was set to the parent structure instead of to the drmvmweventfence which is supposed to be read. drm_read uses the length parameter to copy the event to the user space thus resuling in oob reads.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36960.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b7de6aa84682a3396544fd88cd457f95484573a
Fixed
2f527e3efd37c7c5e85e8aa86308856b619fa59f
Fixed
cef0962f2d3e5fd0660c8efb72321083a1b531a9
Fixed
3cd682357c6167f636aec8ac0efaa8ba61144d36
Fixed
b7bab33c4623c66e3398d5253870d4e88c52dfc0
Fixed
0dbfc73670b357456196130551e586345ca48e1b
Fixed
7b5fd3af4a250dd0a2a558e07b43478748eb5d22
Fixed
deab66596dfad14f1c54eeefdb72428340d72a77
Fixed
a37ef7613c00f2d72c8fc08bd83fb6cc76926c8c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36960.json"