cbcvebase.
CVE-2024-26938
published 2024-05-01

CVE-2024-26938: In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() If we…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() If we have no VBT, or the VBT didn't declare the encoder in question, we won't have the 'devdata' for the encoder. Instead of oopsing just bail early. We won't be able to tell whether the port is DP++ or not, but so be it. (cherry picked from commit 26410896206342c8a80d2b027923e9ee7d33b733)

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 2bea1d7c594dd0643db23a8131c689384d0e5d8c < a891add409e3bc381f4f68c2ce9d953f1865cb1fa891add409e3bc381f4f68c2ce9d953f1865cb1f
linuxlinux>= 2bea1d7c594dd0643db23a8131c689384d0e5d8c < f4bbac954d8f9ab214ea1d4f385de4fa6bd92dd0f4bbac954d8f9ab214ea1d4f385de4fa6bd92dd0
linuxlinux>= 2bea1d7c594dd0643db23a8131c689384d0e5d8c < 94cf2fb6feccd625e5b4e23e1b70f39a206f82ac94cf2fb6feccd625e5b4e23e1b70f39a206f82ac
linuxlinux>= 2bea1d7c594dd0643db23a8131c689384d0e5d8c < 32e39bab59934bfd3f37097d4dd85ac5eb0fd54932e39bab59934bfd3f37097d4dd85ac5eb0fd549
linuxlinux_kernel< 6.1.846.1.84
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.