In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the security issue of unmap the wptr_obj while a queue creation is in progress and passing other bo at same address. (cherry picked from commit 1fc6c8ab45dbee096469c08c13f6099d57a52d6c)
Update Linux/Linux to 336a9186f3a4b65bbd865d93936605ac8a1a3991 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scandrm/amdgpu/userq: fix access to stale wptr mapping affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the security issue of unmap the wptr_obj while a queue creation is in progress and passing other bo at same address. (cherry picked from commit 1fc6c8ab45dbee096469c08c13f6099d57a52d6c)
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5fb2f7fc21a3668e5794cc0d153641b9719713e1 <336a9186f3a4b65bbd865d93936605ac8a1a3991 || >=5fb2f7fc21a3668e5794cc0d153641b9719713e1 <6da7b1242da4455b11c24ce667d1cab1a348c8ea |
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the security issue of unmap the wptr_obj while a queue creation is in progress and passing other bo at same address. (cherry picked from commit 1fc6c8ab45dbee096469c08c13f6099d57a52d6c)
Update Linux/Linux to 336a9186f3a4b65bbd865d93936605ac8a1a3991 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scandrm/amdgpu/userq: fix access to stale wptr mapping affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the security issue of unmap the wptr_obj while a queue creation is in progress and passing other bo at same address. (cherry picked from commit 1fc6c8ab45dbee096469c08c13f6099d57a52d6c)
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5fb2f7fc21a3668e5794cc0d153641b9719713e1 <336a9186f3a4b65bbd865d93936605ac8a1a3991 || >=5fb2f7fc21a3668e5794cc0d153641b9719713e1 <6da7b1242da4455b11c24ce667d1cab1a348c8ea |
| 336a9186f3a4b65bbd865d93936605ac8a1a3991, 6da7b1242da4455b11c24ce667d1cab1a348c8ea |
| Linux/Linuxgeneric | 6.16 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 336a9186f3a4b65bbd865d93936605ac8a1a3991, 6da7b1242da4455b11c24ce667d1cab1a348c8ea |
| Linux/Linuxgeneric | 6.16 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard