PT-2024-34010 · Linux+4 · Linux Kernel+4

Published

2024-07-19

·

Updated

2025-12-07

·

CVE-2024-50177

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.5.0-41-generic #41~22.04.2-Ubuntu
Description: A vulnerability in the Linux kernel's AMDGPU module has been resolved. The issue was causing a UBSAN warning in DML2.1 when programming phantom pipe, due to an unsigned integer overflow. This occurred because the cursor width is explicitly set to 0, triggering calculation logic to overflow for an unsigned int. The kernel's UBSAN check was triggered, resulting in a shift-out-of-bounds error.
Recommendations: To resolve this issue, update the Linux kernel to a version newer than 6.5.0-41-generic #41~22.04.2-Ubuntu. As a temporary workaround, consider adding a guard for checking cursor width before triggering the size calculation to prevent the unsigned integer overflow.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-54066
AZL-54068
BDU:2025-13942
CVE-2024-50177
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu