A vulnerability (CVE-2022-4139) has been found in the Intel GPU driver (i915), which may lead to memory corruption or data leakage from kernel memory. The issue appears starting from Linux kernel 5.4 and affects integrated and discrete Intel GPUs of the 12th generation, including the Tiger Lake, Rocket Lake, Alder Lake, DG1, Raptor Lake, DG2, Arctic Sound, and Meteor Lake families.
The problem is caused by a logical error, which leads to the GPU driver incorrectly resetting the TLB buffers on certain hardware. In some cases, the TLB reset did not occur at all. An improper reset of the TLB buffers may allow a process using the GPU to access physical memory pages that do not belong to that process, which can be exploited to read foreign data or corrupt memory in a foreign process. It is still unclear whether the vulnerability can be used for targeted memory corruption at desired addresses.
Source: opennet.ru
