cbcvebase.
CVE-2024-26660
published 2024-04-02

CVE-2024-26660: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN301…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN301 'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four elements, corresponding to the four calls to stream_enc_regs() in the array initializer. This means that valid indices for this array are 0, 1, 2, and 3. The error message 'stream_enc_regs' 4 <= 5 below, is indicating that there is an attempt to access this array with an index of 5, which is out of bounds. This could lead to undefined behavior Here, eng_id is used as an index to access the stream_enc_regs array. If eng_id is 5, this would result in an out-of-bounds access on the stream_enc_regs array. Thus fixing Buffer overflow error in dcn301_stream_encoder_create reported by Smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn301/dcn301_resource.c:1011 dcn301_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 3a83e4e64bb1522ddac67ffc787d1c38291e1a65 < 42442f74314d41ddc68227047036fa3e7894005442442f74314d41ddc68227047036fa3e78940054
linuxlinux>= 3a83e4e64bb1522ddac67ffc787d1c38291e1a65 < efdd665ce1a1634b8c1dad5e7f6baaef3e131d0aefdd665ce1a1634b8c1dad5e7f6baaef3e131d0a
linuxlinux>= 3a83e4e64bb1522ddac67ffc787d1c38291e1a65 < cd9bd10c59e3c1446680514fd3097c5b00d3712dcd9bd10c59e3c1446680514fd3097c5b00d3712d
linuxlinux>= 3a83e4e64bb1522ddac67ffc787d1c38291e1a65 < a938eab9586eea31cfd129a507f552efae14d738a938eab9586eea31cfd129a507f552efae14d738
linuxlinux>= 3a83e4e64bb1522ddac67ffc787d1c38291e1a65 < 58fca355ad37dcb5f785d9095db5f748b79c5dc258fca355ad37dcb5f785d9095db5f748b79c5dc2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.786.1.78
linuxlinux_kernel>= 6.2 < 6.6.176.6.17
linuxlinux_kernel>= 6.7 < 6.7.56.7.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.