[SRU Bionic, Focal, OEM-5.10, HWE-5.11, Impish, OEM-5.14, Jammy 0/1] CVE-2022-22942

Thadeu Lima de Souza Cascardo cascardo at canonical.com
Thu Jan 27 20:58:10 UTC 2022


[Impact]
Unprivileged users with DRM access on a system using vmwgfx could gain
access to files opened by other processes.

[Fix]
Backports were provided by author and tested on kernels 4.15, 5.4, 5.10,
5.11, 5.13, 5.14 and 5.15.

[Test case]
A program that exercises the changed path gets EFAULT as expected.

[Potential regression]
Only vmwgfx users should be affected.

Mathias Krause (1):
  UBUNTU: SAUCE: drm/vmwgfx: Fix stale file descriptors on failed
    usercopy

 drivers/gpu/drm/vmwgfx/vmwgfx_drv.h     |  5 ++--
 drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 34 ++++++++++++-------------
 drivers/gpu/drm/vmwgfx/vmwgfx_fence.c   |  2 +-
 drivers/gpu/drm/vmwgfx/vmwgfx_kms.c     |  2 +-
 4 files changed, 21 insertions(+), 22 deletions(-)

-- 
2.32.0




More information about the kernel-team mailing list