
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-27008 is a vulnerability discovered in the Linux kernel's DRM (Direct Rendering Manager) subsystem, specifically in the nv04 driver. The vulnerability was found by the Linux Verification Center (linuxtesting.org) using SVACE analysis tool and was disclosed on May 1, 2024 (NVD).
The vulnerability occurs when the Output Resource (dcb->or) value is assigned in the fabricate_dcb_output() function. There is a potential out-of-bounds access to the dac_users array when dcb->or is zero because ffs(dcb->or) is used as an index. The root cause is that the 'or' argument of fabricate_dcb_output() was incorrectly interpreted as a value instead of a number of bits to set. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).
The vulnerability could lead to an out-of-bounds access in the Linux kernel's DRM subsystem, potentially resulting in system crashes or other undefined behavior. This affects systems running the Linux kernel with the NVIDIA nv04 graphics driver (NVD).
The vulnerability requires local access and low privileges to exploit. It has been classified as having low attack complexity, requiring no user interaction to exploit (NVD).
The vulnerability has been fixed by utilizing macros from 'enum nouveau_or' in calls instead of hardcoding values. The fix has been implemented in various Linux kernel versions including 5.10.216-1~deb10u1 for Debian 10, 6.8.0-38.38 for Ubuntu 24.04 LTS, and other distributions. Users should update their kernel to the patched versions (Kernel Patch).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."