Bug 1228061 (CVE-2022-48849) - VUL-0: CVE-2022-48849: kernel: drm/amdgpu: bypass tiling flag check in virtual display case (v2)
Summary: VUL-0: CVE-2022-48849: kernel: drm/amdgpu: bypass tiling flag check in virtua...
Status: NEW
Alias: CVE-2022-48849
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Kernel Bugs
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/414267/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-48849:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-17 13:02 UTC by SMASH SMASH
Modified: 2024-07-17 13:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-07-17 13:02:52 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: bypass tiling flag check in virtual display case (v2)

vkms leverages common amdgpu framebuffer creation, and
also as it does not support FB modifier, there is no need
to check tiling flags when initing framebuffer when virtual
display is enabled.

This can fix below calltrace:

amdgpu 0000:00:08.0: GFX9+ requires FB check based on format modifier
WARNING: CPU: 0 PID: 1023 at drivers/gpu/drm/amd/amdgpu/amdgpu_display.c:1150 amdgpu_display_framebuffer_init+0x8e7/0xb40 [amdgpu]

v2: check adev->enable_virtual_display instead as vkms can be
	enabled in bare metal as well.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-48849
https://www.cve.org/CVERecord?id=CVE-2022-48849
https://git.kernel.org/stable/c/cb29021be49858059138f75d6311a7c35a9379b2
https://git.kernel.org/stable/c/e2b993302f40c4eb714ecf896dd9e1c5be7d4cd7
https://git.kernel.org/stable/c/fcd1d79aa943fff4fbaa0cce1d576995a7960699
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2022/CVE-2022-48849.mbox
https://bugzilla.redhat.com/show_bug.cgi?id=2298190