CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of indirect buffer object (BO) handles in the v3d driver, where a failure to validate user-supplied handles can lead to a NULL pointer dereference during indirect command submission. This flaw can allow attackers to trigger kernel crashes or potentially execute arbitrary code, impacting system stability and security. Organizations utilizing Linux systems with graphics processing capabilities should prioritize addressing this vulnerability to mitigate risks associated with user input handling in the kernel.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject invalid indirect BO handle in indirect CSD setup v3d_get_cpu_indirect_csd_params() looks up the indirect buffer object from a userspace-supplied handle but never checks the result. A bogus or stale handle makes drm_gem_object_lookup() return NULL, which is then stored in info->indirect and only dereferenced later when the indirect CSD job runs, turning a userspace mistake into a NULL pointer dereference in the kernel. Bail out with -ENOENT as soon as the lookup fails, so the bad handle is rejected at submission time.