PT-2024-21476 · Linux+7 · Linux Kernel+7
Fangzhi Zuo
·
Published
2024-02-07
·
Updated
2026-05-26
·
CVE-2024-26700
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.3.9-arch1-1
Description
The Linux kernel has a vulnerability in the drm/amd/display module, specifically in the function
drm dp atomic find time slots. This vulnerability is caused by a NULL pointer dereference, which can lead to a kernel crash. The issue is specific to the RV platform and is triggered by a BUG: kernel NULL pointer dereference, address: 0000000000000008. The vulnerability is related to the compute mst dsc configs for link and compute mst dsc configs for state functions in the amdgpu module.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, update to a version later than 6.3.9-arch1-1. If an update is not available, consider temporarily disabling the
drm dp atomic find time slots function or restricting access to the vulnerable module until a patch is available.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu