cbcvebase.
CVE-2024-27045
published 2024-05-01

CVE-2024-27045: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a potential buffer overflow in 'dp_dsc_clock_en_read()' Tell…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a potential buffer overflow in 'dp_dsc_clock_en_read()' Tell snprintf() to store at most 10 bytes in the output buffer instead of 30. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_debugfs.c:1508 dp_dsc_clock_en_read() error: snprintf() is printing too much 30 vs 10

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < ff28893c96c5e0927a4da10cd24a3522ca663515ff28893c96c5e0927a4da10cd24a3522ca663515
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < 440f059837418fac1695b65d3ebc6080d33be877440f059837418fac1695b65d3ebc6080d33be877
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < d346b3e5b25c95d504478507eb867cd3818775abd346b3e5b25c95d504478507eb867cd3818775ab
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < ad76fd30557d6a106c481e4606a981221ca525f7ad76fd30557d6a106c481e4606a981221ca525f7
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < eb9327af3621d26b1d83f767c97a3fe8191a3a65eb9327af3621d26b1d83f767c97a3fe8191a3a65
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < cf114d8d4a8d78df272116a745bb43b48cef65f4cf114d8d4a8d78df272116a745bb43b48cef65f4
linuxlinux>= c06e09b76639657f284bfaf1cce29557a2515e85 < 4b09715f1504f1b6e8dff0e9643630610bc051414b09715f1504f1b6e8dff0e9643630610bc05141
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.9 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.29.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.