CVE-2024-53084 Information

Description

In the Linux kernel the following vulnerability has been resolved:

drm/imagination: Break an object reference loop

When remaining resources are being cleaned up on driver close outstanding VM mappings may result in resources being leaked due to an object reference loop as shown below with each object (or set of objects) referencing the object below it:

PVR GEM Object
GPU scheduler inished\ fence
GPU scheduler “scheduled” fence
PVR driver “done” fence
PVR Context
PVR VM Context
PVR VM Mappings
PVR GEM Object

The reference that the PVR VM Context has on the VM mappings is a soft one in the sense that the freeing of outstanding VM mappings is done as part of VM context destruction; no reference counts are involved as is the case for all the other references in the loop.

To break the reference loop during cleanup free the outstanding VM mappings before destroying the PVR Context associated with the VM context.

Reference

https://git.kernel.org/stable/c/cb86db12b290ed07d05df00d99fa150bb123e80e https://git.kernel.org/stable/c/b04ce1e718bd55302b52d05d6873e233cb3ec7a1

Share on: