CVE-2024-27008
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-27008 is a vulnerability discovered in the Linux kernel's DRM (Direct Rendering Manager) subsystem, specifically in the nv04 driver. The vulnerability was found by the Linux Verification Center (linuxtesting.org) using SVACE analysis tool and was disclosed on May 1, 2024 (NVD).

Technical details

The vulnerability occurs when the Output Resource (dcb->or) value is assigned in the fabricate_dcb_output() function. There is a potential out-of-bounds access to the dac_users array when dcb->or is zero because ffs(dcb->or) is used as an index. The root cause is that the 'or' argument of fabricate_dcb_output() was incorrectly interpreted as a value instead of a number of bits to set. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability could lead to an out-of-bounds access in the Linux kernel's DRM subsystem, potentially resulting in system crashes or other undefined behavior. This affects systems running the Linux kernel with the NVIDIA nv04 graphics driver (NVD).

Exploitability

The vulnerability requires local access and low privileges to exploit. It has been classified as having low attack complexity, requiring no user interaction to exploit (NVD).

Mitigation and workarounds

The vulnerability has been fixed by utilizing macros from 'enum nouveau_or' in calls instead of hardcoding values. The fix has been implemented in various Linux kernel versions including 5.10.216-1~deb10u1 for Debian 10, 6.8.0-38.38 for Ubuntu 24.04 LTS, and other distributions. Users should update their kernel to the patched versions (Kernel Patch).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.90-1

Fixed

bullseye

linux: 5.10.216-1

Fixed

sid

linux: 6.8.9-1

Fixed

trixie

linux: 6.8.9-1

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-oracle-5.4
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-gcp-fips
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-oracle
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management