CVE-2024-26984

Source
https://cve.org/CVERecord?id=CVE-2024-26984
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26984.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26984
Downstream
Related
Published
2024-05-01T05:27:20.506Z
Modified
2026-05-28T03:52:38.338962934Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
nouveau: fix instmem race condition around ptr stores
Details

In the Linux kernel, the following vulnerability has been resolved:

nouveau: fix instmem race condition around ptr stores

Running a lot of VK CTS in parallel against nouveau, once every few hours you might see something like this crash.

BUG: kernel NULL pointer dereference, address: 0000000000000008 PGD 8000000114e6e067 P4D 8000000114e6e067 PUD 109046067 PMD 0 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 7 PID: 53891 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27 Hardware name: Gigabyte Technology Co., Ltd. Z390 I AORUS PRO WIFI/Z390 I AORUS PRO WIFI-CF, BIOS F8 11/05/2021 RIP: 0010:gp100vmmpgt_mem+0xe3/0x180 [nouveau] Code: c7 48 01 c8 49 89 45 58 85 d2 0f 84 95 00 00 00 41 0f b7 46 12 49 8b 7e 08 89 da 42 8d 2c f8 48 8b 47 08 41 83 c7 01 48 89 ee <48> 8b 40 08 ff d0 0f 1f 00 49 8b 7e 08 48 89 d9 48 8d 75 04 48 c1 RSP: 0000:ffffac20c5857838 EFLAGS: 00010202 RAX: 0000000000000000 RBX: 00000000004d8001 RCX: 0000000000000001 RDX: 00000000004d8001 RSI: 00000000000006d8 RDI: ffffa07afe332180 RBP: 00000000000006d8 R08: ffffac20c5857ad0 R09: 0000000000ffff10 R10: 0000000000000001 R11: ffffa07af27e2de0 R12: 000000000000001c R13: ffffac20c5857ad0 R14: ffffa07a96fe9040 R15: 000000000000001c FS: 00007fe395eed7c0(0000) GS:ffffa07e2c980000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 000000011febe001 CR4: 00000000003706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace:

...

? gp100vmmpgtmem+0xe3/0x180 [nouveau] ? gp100vmmpgtmem+0x37/0x180 [nouveau] nvkmvmmiter+0x351/0xa20 [nouveau] ? __pfxnvkmvmmrefptes+0x10/0x10 [nouveau] ? __pfxgp100vmmpgtmem+0x10/0x10 [nouveau] ? __pfxgp100vmmpgtmem+0x10/0x10 [nouveau] ? __lock_acquire+0x3ed/0x2170 ? __pfxgp100vmmpgtmem+0x10/0x10 [nouveau] nvkmvmmptesgetmap+0xc2/0x100 [nouveau] ? __pfxnvkmvmmrefptes+0x10/0x10 [nouveau] ? _pfxgp100vmmpgtmem+0x10/0x10 [nouveau] nvkmvmmmaplocked+0x224/0x3a0 [nouveau]

Adding any sort of useful debug usually makes it go away, so I hand wrote the function in a line, and debugged the asm.

Every so often pt->memory->ptrs is NULL. This ptrs ptr is set in the nv50instobjacquire called from nvkm_kmap.

If Thread A and Thread B both get to nv50instobjacquire around the same time, and Thread A hits the refcountset line, and in lockstep thread B succeeds at refcountincnotzero, there is a chance the ptrs value won't have been stored since refcountset is unordered. Force a memory barrier here, I picked smpmb, since we want it on all CPUs and it's write followed by a read.

v2: use paired smprmb/smpwmb.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26984.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
be55287aa5ba6895e9d4d3ed2f08a1be7a065957
Fixed
bba8ec5e9b16649d85bc9e9086bf7ae5b5716ff9
Fixed
1bc4825d4c3ec6abe43cf06c3c39d664d044cbf7
Fixed
13d76b2f443dc371842916dd8768009ff1594716
Fixed
3ab056814cd8ab84744c9a19ef51360b2271c572
Fixed
ad74d208f213c06d860916ad40f609ade8c13039
Fixed
a019b44b1bc6ed224c46fb5f88a8a10dd116e525
Fixed
21ca9539f09360fd83654f78f2c361f2f5ddcb52
Fixed
fff1386cc889d8fb4089d285f883f8cba62d82ce

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26984.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.313
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.275
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.216
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.157
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.88
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.29
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26984.json"