PT-2024-10458 · Linux+5 · Linux Kernel+5
Published
2024-07-30
·
Updated
2025-02-03
·
CVE-2024-42119
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the drm/amd/display component of the Linux kernel, where an error in handling unknown engine id values can lead to overrun issues. The problem arises because ENGINE ID UNKNOWN is set to -1, which cannot be used as an array index, and it also indicates that the engine is uninitialized and does not require free audio. This issue has been resolved by skipping the search for free audio when the engine id is unknown and returning NULL instead.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu