cbcvebase.
CVE-2024-40916
published 2024-07-12

CVE-2024-40916: In the Linux kernel, the following vulnerability has been resolved: drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found When reading…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found When reading EDID fails and driver reports no modes available, the DRM core adds an artificial 1024x786 mode to the connector. Unfortunately some variants of the Exynos HDMI (like the one in Exynos4 SoCs) are not able to drive such mode, so report a safe 640x480 mode instead of nothing in case of the EDID reading failure. This fixes the following issue observed on Trats2 board since commit 13d5b040363c ("drm/exynos: do not return negative values from .get_modes()"): [drm] Exynos DRM: using 11c00000.fimd device for DMA mapping operations exynos-drm exynos-drm: bound 11c00000.fimd (ops fimd_component_ops) exynos-drm exynos-drm: bound 12c10000.mixer (ops mixer_component_ops) exynos-dsi 11c80000.dsi: [drm:samsung_dsim_host_attach] Attached s6e8aa0 device (lanes:4 bpp:24 mode-flags:0x10b) exynos-drm exynos-drm: bound 11c80000.dsi (ops exynos_dsi_component_ops) exynos-drm exynos-drm: bound 12d00000.hdmi (ops hdmi_component_ops) [drm] Initialized exynos 1.1.0 20180330 for exynos-drm on minor 1 exynos-hdmi 12d00000.hdmi: [drm:hdmiphy_enable.part.0] *ERROR* PLL could not reach steady state panel-samsung-s6e8aa0 11c80000.dsi.0: ID: 0xa2, 0x20, 0x8c exynos-mixer 12c10000.mixer: timeout waiting for VSYNC ------------[ cut here ]------------ WARNING: CPU: 1 PID: 11 at drivers/gpu/drm/drm_atomic_helper.c:1682 drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8 [CRTC:70:crtc-1] vblank wait timed out Modules linked in: CPU: 1 PID: 11 Comm: kworker/u16:0 Not tainted 6.9.0-rc5-next-20240424 #14913 Hardware name: Samsung Exynos (Flattened Device Tree) Workqueue: events_unbound deferred_probe_work_func Call trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x68/0x88 dump_stack_lvl from __warn+0x7c/0x1c4 __warn from warn_slowpath_fmt+0x11c/0x1a8 warn_slowpath_fmt from drm_atomic_helper_wait_for_vblanks.part.0

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 13d5b040363c7ec0ac29c2de9cf661a24a8aa531 < 510a6c0dfa6ec61d07a4b64698d8dc60045bd632510a6c0dfa6ec61d07a4b64698d8dc60045bd632
linuxlinux>= 13d5b040363c7ec0ac29c2de9cf661a24a8aa531 < 799d4b392417ed6889030a5b2335ccb6dcf030ab799d4b392417ed6889030a5b2335ccb6dcf030ab
linuxlinux>= 348aa3d47e8bc2fa4e5b8079554724343631b82a < e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222
linuxlinux>= 5.10.215 < 5.10.2215.10.221
linuxlinux>= 5.15.154 < 5.15.1625.15.162
linuxlinux>= 5.4.274 < 5.4.2795.4.279
linuxlinux>= 6.1.84 < 6.1.956.1.95
linuxlinux>= 6.6.24 < 6.6.356.6.35
linuxlinux>= 6.7.12 < 6.86.8
linuxlinux>= 6.8.3 < 6.96.9
linuxlinux>= 8f914db6fe252c5e78a9b8b03adc1b0a33aec25d < c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ecc3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec
linuxlinux>= 912c149a52c37a2f8199449360bf392ae4ef7f4c < 6d6bb258d886e124e5a5328e947b36fdcb3a60286d6bb258d886e124e5a5328e947b36fdcb3a6028
linuxlinux>= a8cb3b072403ce0748d368278bc7ab87d15e90a7 < 4dfffb50316c761c59386c9b002a10ac6d7bb6c94dfffb50316c761c59386c9b002a10ac6d7bb6c9
linuxlinux>= b71ae5fb2dd3c89c66efa613dccffc45c246c8b9 < 35bcf16b4a28c10923ff391d14f6ed0ae471ee5f35bcf16b4a28c10923ff391d14f6ed0ae471ee5f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.