PT-2024-33745 · Linux+7 · Linux Kernel+7
Published
2024-10-21
·
Updated
2026-05-26
·
CVE-2024-49905
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
A null pointer dereference issue has been resolved in the Linux kernel. The problem occurred because the
afb variable in the amdgpu dm plane handle cursor update function was assumed to be null but was used later in the code without a null check. This could potentially lead to a null pointer dereference. The issue has been fixed by adding a null check for the afb variable.Recommendations:
For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider disabling the
amdgpu dm plane handle cursor update function until a patch is available. Restrict access to the vulnerable module amdgpu dm plane to minimize the risk of exploitation. Avoid using the afb variable in the affected code until the issue is resolved.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu