gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees
it, so we can't dereference mapping afterwards. The cache itself
outlives the mapping, so use the cache local variable instead.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265bhttps://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157