CVE-2024-42264·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Prevent out of bounds access in performance query extensions Check that the number of perfmons userspace is passing in the copy and reset extensions is not greater than the internal kernel storage where the ids will be copied into. (cherry picked from commit f32b5128d2c440368b5bf3a7a356823e235caabb)
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.4
- Published
- 2024-08-17
Affected versions
From: 6.8
Until: 6.10.4
Fixed in: 6.10.4
How to fix this CVE
Systems running Linux kernel versions 6.8 through 6.10.3 should be updated to kernel 6.10.4 or later to resolve a buffer overflow vulnerability in the DRM v3d graphics driver's performance query extension handling. This vulnerability could allow local users with sufficient privileges to trigger memory corruption by passing an excessive number of performance monitor identifiers. Apply the kernel update immediately, especially on systems with direct GPU access or running untrusted workloads.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run `uname -r` to display the currently running kernel version and verify if it falls within the affected range (6.8.x to 6.10.3)
- Check if the v3d graphics driver is loaded by running `lsmod | grep v3d` or `modinfo v3d` to confirm exposure
- Search system logs for drm/v3d related errors using `dmesg | grep -i 'v3d\|perfmon'` or `journalctl -g 'v3d'`
- After patching, confirm the new kernel version with `uname -r` and verify it is 6.10.4 or higher, then reboot if necessary
FAQ
What is CVE-2024-42264?
This vulnerability is a buffer overflow in the Linux kernel's DRM v3d (3D graphics) driver performance query extension. An improperly validated userspace input allowing excessive performance monitor IDs can overflow kernel-internal storage, potentially causing memory corruption or system instability.
Is CVE-2024-42264 being actively exploited?
No, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and no public exploit code is currently available.
What versions of Kernel are affected by CVE-2024-42264?
Kernel versions 6.8 through 6.10.3 are vulnerable; the fix is included in kernel 6.10.4 and later.
How do I check if my server is vulnerable to CVE-2024-42264?
Run `uname -r` and check if the output shows a version between 6.8 and 6.10.3; additionally verify v3d driver presence with `lsmod | grep v3d`.
Does Defensia detect CVE-2024-42264?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-42264 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-42264. Free for 1 server.
Get started free