cbcvebase.
CVE-2024-42119
published 2024-07-30

CVE-2024-42119: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip finding free audio for unknown engine_id [WHY] ENGINE_ID_UNKNOWN = -1…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip finding free audio for unknown engine_id [WHY] ENGINE_ID_UNKNOWN = -1 and can not be used as an array index. Plus, it also means it is uninitialized and does not need free audio. [HOW] Skip and return NULL. This fixes 2 OVERRUN issues reported by Coverity.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 9eb4db08a808e3a3ba59193aeb84a57a6dc4d8c99eb4db08a808e3a3ba59193aeb84a57a6dc4d8c9
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < eacca028a623f608607d02457122ee5284491e18eacca028a623f608607d02457122ee5284491e18
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < ffa7bd3ca9cfa902b857d1dc9a5f46fededf86c8ffa7bd3ca9cfa902b857d1dc9a5f46fededf86c8
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < afaaebdee9bb9f26d9e13cc34b33bd0a7bf59488afaaebdee9bb9f26d9e13cc34b33bd0a7bf59488
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 874261358d31fc772f2823604167e670983cc1ca874261358d31fc772f2823604167e670983cc1ca
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 95ad20ee3c4efbb91f9a4ab08e070aa3697f587995ad20ee3c4efbb91f9a4ab08e070aa3697f5879
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 881fb6afc0004c5e6392ae2848f825bf051dae14881fb6afc0004c5e6392ae2848f825bf051dae14
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 1357b2165d9ad94faa4c4a20d5e2ce29c2ff29c31357b2165d9ad94faa4c4a20d5e2ce29c2ff29c3
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.15 < 4.19.3184.19.318
linuxlinux_kernel>= 4.20 < 5.4.2805.4.280
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 5.5 < 5.10.2225.10.222
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.