cbcvebase.
CVE-2024-42121
published 2024-07-30

CVE-2024-42121: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check index msg_id before read or write [WHAT] msg_id is used as an array…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check index msg_id before read or write [WHAT] msg_id is used as an array index and it cannot be a negative value, and therefore cannot be equal to MOD_HDCP_MESSAGE_ID_INVALID (-1). [HOW] Check whether msg_id is valid before reading and setting. This fixes 4 OVERRUN issues reported by Coverity.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < b5b8837d066cc182ff69fb5629ad32ade5484567b5b8837d066cc182ff69fb5629ad32ade5484567
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < fbb0701af9734cff13917a4b98b5ee9da2fde48dfbb0701af9734cff13917a4b98b5ee9da2fde48d
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < ae91ffbc8b8d942e3e7f188728cad557b7ed5ee4ae91ffbc8b8d942e3e7f188728cad557b7ed5ee4
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 9933eca6ada0cd612e19522e7a319bcef464c0eb9933eca6ada0cd612e19522e7a319bcef464c0eb
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a31ea49dc8064a557565725cf045944307476a6ea31ea49dc8064a557565725cf045944307476a6e
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 59d99deb330af206a4541db0c4da8f73880fba0359d99deb330af206a4541db0c4da8f73880fba03
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.15 < 5.10.2225.10.222
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.