CVE-2024-44993
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2024-44993 affects the Linux kernel's DRM (Direct Rendering Manager) V3D driver. The vulnerability was discovered when enabling UBSAN on Raspberry Pi 5, revealing an out-of-bounds read in the v3d_csd_job_run() function. The issue occurs because the UAPI provides only seven configuration registers while the code attempts to read an eighth position of a u32 array (Kernel Patch).

Technical details

The vulnerability is an array-index-out-of-bounds issue in drivers/gpu/drm/v3d/v3dsched.c:320:3, where an index 7 is accessed but is out of range for type '_u32 [7]'. The issue affects Linux kernel versions from 6.8 up to (excluding) 6.10.7, as well as release candidates 6.11-rc1 through 6.11-rc3. The vulnerability has been assigned a CVSS v3.1 base score of 7.1 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H (NVD).

Impact

The vulnerability could allow an attacker with local access to cause an out-of-bounds read, potentially leading to information disclosure or system crashes. This particularly affects systems using the V3D graphics driver, such as the Raspberry Pi 5 (Kernel Patch).

Mitigation and workarounds

A fix has been implemented in the Linux kernel that modifies the v3d_csd_job_run() function to access only seven positions on the '_u32 [7]' array. For V3D 7.1, which has an eighth configuration register, the fix ensures it remains unused by explicitly writing 0 to V3DV7CSDQUEUED_CFG7. Users should update to patched kernel versions that include this fix (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59030HIGH7.5
  • Linux DebianLinux Debian
  • pdns-recursor
NoYesDec 09, 2025
CVE-2025-59029MEDIUM5.3
  • Linux DebianLinux Debian
  • pdns-recursor
NoYesDec 09, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management