CVE-2021-47348
published 2024-05-21CVE-2021-47348: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes…
PriorityP342critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.99%
58.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid HDCP over-read and corruption
Instead of reading the desired 5 bytes of the actual target field,
the code was reading 8. This could result in a corrupted value if the
trailing 3 bytes were non-zero, so instead use an appropriately sized
and zero-initialized bounce buffer, and read only 5 bytes before casting
to u64.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4c283fdac08abf3211533f70623c90a34f41d08d < c5b518f4b98dbb2bc31b6a55e6aaa1e0e2948f2e | c5b518f4b98dbb2bc31b6a55e6aaa1e0e2948f2e |
| linux | linux | >= 4c283fdac08abf3211533f70623c90a34f41d08d < 44c7c901cb368a9f2493748f213b247b5872639f | 44c7c901cb368a9f2493748f213b247b5872639f |
| linux | linux | >= 4c283fdac08abf3211533f70623c90a34f41d08d < 3b2b93a485fb7a970bc8b5daef16f4cf579d172f | 3b2b93a485fb7a970bc8b5daef16f4cf579d172f |
| linux | linux | >= 4c283fdac08abf3211533f70623c90a34f41d08d < 06888d571b513cbfc0b41949948def6cb81021b2 | 06888d571b513cbfc0b41949948def6cb81021b2 |
| linux | linux_kernel | < 5.10.51 | 5.10.51 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.18 | 5.12.18 |
| linux | linux_kernel | >= 5.13 < 5.13.3 | 5.13.3 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jq29-8xm6-ccxq: In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid HDCP over-read and corruption
Instead of reading the desi
ghsa_unreviewed·2024-05-21
CVE-2021-47348 [CRITICAL] CWE-119 GHSA-jq29-8xm6-ccxq: In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid HDCP over-read and corruption
Instead of reading the desi
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid HDCP over-read and corruption
Instead of reading the desired 5 bytes of the actual target field,
the code was reading 8. This could result in a corrupted value if the
trailing 3 bytes were non-zero, so instead use an appropriately sized
and zero-initialized bounce buffer, and read only 5 bytes before casting
to u64.
OSV
CVE-2021-47348: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desire
osv·2024-05-21·CVSS 9.1
CVE-2021-47348 [CRITICAL] CVE-2021-47348: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desire
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the actual target field, the code was reading 8. This could result in a corrupted value if the trailing 3 bytes were non-zero, so instead use an appropriately sized and zero-initialized bounce buffer, and read only 5 bytes before casting to u64.
Red Hat
kernel: drm/amd/display: Avoid HDCP over-read and corruption
vendor_redhat·2024-05-21·CVSS 9.1
CVE-2021-47348 [CRITICAL] kernel: drm/amd/display: Avoid HDCP over-read and corruption
kernel: drm/amd/display: Avoid HDCP over-read and corruption
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid HDCP over-read and corruption
Instead of reading the desired 5 bytes of the actual target field,
the code was reading 8. This could result in a corrupted value if the
trailing 3 bytes were non-zero, so instead use an appropriately sized
and zero-initialized bounce buffer, and read only 5 bytes before casting
to u64.
A vulnerability was found in the Linux kernel's AMD display driver, where it incorrectly read 8 bytes instead of the intended 5 bytes of data related to HDCP (High-bandwidth Digital Content Protection). This error could lead to data corruption if the extra 3 bytes contained non-zero values. The issue was addressed by ensuring
Debian
CVE-2021-47348: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis...
vendor_debian·2021·CVSS 9.1
CVE-2021-47348 [CRITICAL] CVE-2021-47348: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis...
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the actual target field, the code was reading 8. This could result in a corrupted value if the trailing 3 bytes were non-zero, so instead use an appropriately sized and zero-initialized bounce buffer, and read only 5 bytes before casting to u64.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/06888d571b513cbfc0b41949948def6cb81021b2https://git.kernel.org/stable/c/3b2b93a485fb7a970bc8b5daef16f4cf579d172fhttps://git.kernel.org/stable/c/44c7c901cb368a9f2493748f213b247b5872639fhttps://git.kernel.org/stable/c/c5b518f4b98dbb2bc31b6a55e6aaa1e0e2948f2ehttps://git.kernel.org/stable/c/06888d571b513cbfc0b41949948def6cb81021b2https://git.kernel.org/stable/c/3b2b93a485fb7a970bc8b5daef16f4cf579d172fhttps://git.kernel.org/stable/c/44c7c901cb368a9f2493748f213b247b5872639fhttps://git.kernel.org/stable/c/c5b518f4b98dbb2bc31b6a55e6aaa1e0e2948f2e
2024-05-21
Published