SB2024070416 - Improper resource shutdown or release in Linux kernel drm panfrost driver
Published: July 4, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2024-35951)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the panfrost_mmu_map_fault_addr() and sg_free_table() functions in drivers/gpu/drm/panfrost/panfrost_mmu.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/31806711e8a4b75e09b1c43652f2a6420e6e1002
- https://git.kernel.org/stable/c/e18070c622c63f0cab170348e320454728c277aa
- https://git.kernel.org/stable/c/1fc9af813b25e146d3607669247d0f970f5a87c3
- http://www.openwall.com/lists/oss-security/2024/05/30/2
- http://www.openwall.com/lists/oss-security/2024/05/30/1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.28
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.7