CVE-2024-46699·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Disable preemption while updating GPU stats We forgot to disable preemption around the write_seqcount_begin/end() pair while updating GPU stats: [ ] WARNING: CPU: 2 PID: 12 at include/linux/seqlock.h:221 __seqprop_assert.isra.0+0x128/0x150 [v3d] [ ] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched] <...snip...> [ ] Call trace: [ ] __seqprop_assert.isra.0+0x128/0x150 [v3d] [ ] v3d_job_start_stats.isra.0+0x90/0x218 [v3d] [ ] v3d_bin_job_run+0x23c/0x388 [v3d] [ ] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched] [ ] process_one_work+0x62c/0xb48 [ ] worker_thread+0x468/0x5b0 [ ] kthread+0x1c4/0x1e0 [ ] ret_from_fork+0x10/0x20 Fix it.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.8
- Published
- 2024-09-13
Affected versions
From: 6.10
Until: 6.10.8
Fixed in: 6.10.8
How to fix this CVE
Update the Linux kernel to version 6.10.8 or later to resolve a race condition in the DRM v3d driver's GPU statistics update routine. This vulnerability occurs when preemption is not properly disabled during seqcount operations, potentially causing kernel warnings and system instability. Apply the kernel update through your distribution's package manager and reboot the system.
sudo dnf check-update kernel && sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r
- Verify if v3d GPU driver is loaded: lsmod | grep v3d (relevant for systems with Broadcom VideoCore VI GPUs)
- Search system logs for seqcount assertion warnings: grep -i 'seqprop_assert\|v3d_job_start_stats' /var/log/kern.log /var/log/syslog
- Confirm kernel update applied: verify uname -r returns 6.10.8 or later, and check dmesg for successful module reload
FAQ
What is CVE-2024-46699?
CVE-2024-46699 is a race condition in the Linux kernel's DRM v3d (3D graphics) driver where preemption is not disabled during GPU statistics updates, causing seqcount assertion failures and potential kernel instability on systems with Broadcom VideoCore VI GPUs.
Is CVE-2024-46699 being actively exploited?
No, CVE-2024-46699 is not listed on the CISA KEV catalog and no public exploits are available. However, it causes kernel warnings that can disrupt system reliability.
What versions of Kernel are affected by CVE-2024-46699?
Linux kernel versions 6.10 through 6.10.8 are affected. The vulnerability was patched in kernel 6.10.8 and later.
How do I check if my server is vulnerable to CVE-2024-46699?
Run 'uname -r' to check your kernel version. If it reports 6.10 through 6.10.7, you are vulnerable. Additionally, run 'lsmod | grep v3d' to confirm the v3d driver is in use; systems without v3d loaded are not affected.
Does Defensia detect CVE-2024-46699?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-46699 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-46699. Free for 1 server.
Get started free