cbcvebase.
CVE-2024-42120
published 2024-07-30

CVE-2024-42120: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check pipe offset before setting vblank pipe_ctx has a size of MAX_PIPES…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check pipe offset before setting vblank pipe_ctx has a size of MAX_PIPES so checking its index before accessing the array. This fixes an OVERRUN issue reported by Coverity.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < b2e9abc95583ac7bbb2c47da4d476a798146dfd6b2e9abc95583ac7bbb2c47da4d476a798146dfd6
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 0b3702f9d43d163fd05e43b7d7e22e766dbef3290b3702f9d43d163fd05e43b7d7e22e766dbef329
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < d2c3645a4a5ae5d933b4116c305d9d82b8199dbfd2c3645a4a5ae5d933b4116c305d9d82b8199dbf
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 96bf81cc1bd058bb8af6e755a548e926e934dfd196bf81cc1bd058bb8af6e755a548e926e934dfd1
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < c5ec2afeeee4c91cebc4eff6d4f1ecf4047259f4c5ec2afeeee4c91cebc4eff6d4f1ecf4047259f4
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 5396a70e8cf462ec5ccf2dc8de103c79de9489e65396a70e8cf462ec5ccf2dc8de103c79de9489e6
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.15 < 5.10.2225.10.222
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.