PT-2024-21476 · Linux+7 · Linux Kernel+7

Fangzhi Zuo

·

Published

2024-02-07

·

Updated

2026-05-26

·

CVE-2024-26700

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.9-arch1-1
Description The Linux kernel has a vulnerability in the drm/amd/display module, specifically in the function drm dp atomic find time slots. This vulnerability is caused by a NULL pointer dereference, which can lead to a kernel crash. The issue is specific to the RV platform and is triggered by a BUG: kernel NULL pointer dereference, address: 0000000000000008. The vulnerability is related to the compute mst dsc configs for link and compute mst dsc configs for state functions in the amdgpu module.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, update to a version later than 6.3.9-arch1-1. If an update is not available, consider temporarily disabling the drm dp atomic find time slots function or restricting access to the vulnerable module until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-54963
BDU:2025-03616
CVE-2024-26700
DSA-5658-1
INFSA-2024_9315
OPENSUSE-SU-2024_1644-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:1644-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2190-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1
USN-7829-1
USN-7829-2
USN-7829-3
USN-7829-4
USN-7829-5
USN-7829-6
USN-7933-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu