Bug 1790044 (CVE-2019-19927) - CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
Summary: CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm...
Keywords:
Status: NEW
Alias: CVE-2019-19927
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1790045
Blocks: 1790046
TreeView+ depends on / blocked
 
Reported: 2020-01-11 14:33 UTC by Pedro Sampaio
Modified: 2020-01-13 12:53 UTC (History)
44 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Pedro Sampaio 2020-01-11 14:33:39 UTC
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on
kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some
operations can lead to slab-out-of-bounds read access in ttm_put_pages in
drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm
module.

References:

https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19927

Upstream patch:

https://github.com/torvalds/linux/commit/453393369dc9806d2455151e329c599684762428
https://github.com/torvalds/linux/commit/a66477b0efe511d98dde3e4aaeb189790e6f0a39
https://github.com/torvalds/linux/commit/ac1e516d5a4c56bf0cb4a3dfc0672f689131cfd4

Comment 1 Pedro Sampaio 2020-01-11 14:34:17 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1790045]

Comment 2 Justin M. Forbes 2020-01-13 12:53:55 UTC
This was fixed for Fedora with the 5.1 kernel rebases.


Note You need to log in before you can comment on or make changes to this bug.