PT-2024-3402 · Linux · Linux Kernel

Published

2024-02-22

·

Updated

2025-01-07

·

CVE-2024-26728

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.5.0-asdn+
Description: The vulnerability is related to a null-pointer dereference in the Linux kernel's drm/amd/display module. This occurs when the kernel attempts to read EDID (Extended Display Identification Data) from a display device without properly checking if the required data is available. The issue arises when running the igt@kms force connector basic test in a system with DCN2.1 and an HDMI connector. This can lead to a kernel crash or potentially allow an attacker to execute arbitrary code.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the null-pointer dereference in the drm/amd/display module. Specifically, versions 6.5.0-asdn+ and later should include this fix. Ensure that all affected systems are updated to prevent potential exploitation of this vulnerability.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-03674
CVE-2024-26728

Affected Products

Linux Kernel