In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix opregion leak
Being part o the display, ideally the setup and cleanup would be done by display itself. However this is a bigger refactor that needs to be done on both i915 and xe. For now, just fix the leak:
unreferenced object 0xffff8881a0300008 (size 192): comm "modprobe", pid 4354, jiffies 4295647021 hex dump (first 32 bytes): 00 00 87 27 81 88 ff ff 18 80 9b 00 00 c9 ff ff ...'............ 18 81 9b 00 00 c9 ff ff 00 00 00 00 00 00 00 00 ................ backtrace (crc 99260e31): [<ffffffff823ce65b>] kmemleakalloc+0x4b/0x80 [<ffffffff81493be2>] kmalloctracenoprof+0x312/0x3d0 [<ffffffffa1345679>] intelopregionsetup+0x89/0x700 [xe] [<ffffffffa125bfaf>] xedisplayinitnoirq+0x2f/0x90 [xe] [<ffffffffa1199ec3>] xedeviceprobe+0x7a3/0xbf0 [xe] [<ffffffffa11f3713>] xepciprobe+0x333/0x5b0 [xe] [<ffffffff81af6be8>] localpciprobe+0x48/0xb0 [<ffffffff81af8778>] pcideviceprobe+0xc8/0x280 [<ffffffff81d09048>] reallyprobe+0xf8/0x390 [<ffffffff81d0937a>] _driverprobedevice+0x8a/0x170 [<ffffffff81d09503>] driverprobedevice+0x23/0xb0 [<ffffffff81d097b7>] _driverattach+0xc7/0x190 [<ffffffff81d0628d>] busforeachdev+0x7d/0xd0 [<ffffffff81d0851e>] driverattach+0x1e/0x30 [<ffffffff81d07ac7>] busadddriver+0x117/0x250
(cherry picked from commit 6f4e43a2f771b737d991142ec4f6d4b7ff31fbb4)
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f7ecdd9853dd9f34e7cdfdadfb70b8f40644ebb4",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "xe_display_init_noirq",
"file": "drivers/gpu/drm/xe/display/xe_display.c"
},
"id": "CVE-2024-44980-049fa00a",
"signature_type": "Function",
"digest": {
"length": 323.0,
"function_hash": "215164835082943005399671750102655134427"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "xe_display_init_noirq",
"file": "drivers/gpu/drm/xe/display/xe_display.c"
},
"id": "CVE-2024-44980-37dfec42",
"signature_type": "Function",
"digest": {
"length": 328.0,
"function_hash": "242215184997935903028023629080669767578"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f7ecdd9853dd9f34e7cdfdadfb70b8f40644ebb4",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/gpu/drm/xe/display/xe_display.c"
},
"id": "CVE-2024-44980-42ad3fd4",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"234461493811424197431967808685869527486",
"141130698553973187088793215071047654691",
"42063766874834672096840953881159320012",
"9984072682187016756273919911351784542",
"210177135808769996124462353505570089043",
"4294934109039916065019046846346514932",
"89779535892474695080144330095563325980",
"272138311545376215858849011429480166079",
"162809229208257788003014175886549384985"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4b2a0ae1a31fd3d1b5ca18ee08319b479cf9b5f",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/gpu/drm/xe/display/xe_display.c"
},
"id": "CVE-2024-44980-f5b23f95",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"189564734907227616559529391733078301289",
"141130698553973187088793215071047654691",
"42063766874834672096840953881159320012",
"9984072682187016756273919911351784542",
"210177135808769996124462353505570089043",
"4294934109039916065019046846346514932",
"69238332505928546717902566899999654349",
"80616384921989159650089382279331325444",
"249626525116808113827149599327464300735"
]
}
}
]