cbcvebase.
CVE-2024-27040
published 2024-05-01

CVE-2024-27040: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add 'replay' NULL check in 'edp_set_replay_allow_active()' In the first if…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add 'replay' NULL check in 'edp_set_replay_allow_active()' In the first if statement, we're checking if 'replay' is NULL. But in the second if statement, we're not checking if 'replay' is NULL again before calling replay->funcs->replay_set_power_opt(). if (replay == NULL && force_static) return false; ... if (link->replay_settings.replay_feature_enabled && replay->funcs->replay_set_power_opt) { replay->funcs->replay_set_power_opt(replay, *power_opts, panel_inst); link->replay_settings.replay_power_opt_active = *power_opts; } If 'replay' is NULL, this will cause a null pointer dereference. Fixes the below found by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/link/protocols/link_edp_panel_control.c:895 edp_set_replay_allow_active() error: we previously assumed 'replay' could be null (see line 887)

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= c7ddc0a800bc9f681a18c3bdd9f06b61adfabc11 < f610c46771ef1047e46d61807aa7c69cd29e63d8f610c46771ef1047e46d61807aa7c69cd29e63d8
linuxlinux>= c7ddc0a800bc9f681a18c3bdd9f06b61adfabc11 < e7cadd5d3a8ffe334d0229ba9eda4290138d56e7e7cadd5d3a8ffe334d0229ba9eda4290138d56e7
linuxlinux>= c7ddc0a800bc9f681a18c3bdd9f06b61adfabc11 < d0e94f4807ff0df66cf447d6b4bbb8ac830e99c3d0e94f4807ff0df66cf447d6b4bbb8ac830e99c3
linuxlinux>= c7ddc0a800bc9f681a18c3bdd9f06b61adfabc11 < f6aed043ee5d75b3d1bfc452b1a9584b63c8f76bf6aed043ee5d75b3d1bfc452b1a9584b63c8f76b
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.6 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.