cbcvebase.
CVE-2024-42228
published 2024-07-30

CVE-2024-42228: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the…

PriorityP428high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001. V2: To really improve the handling we would actually need to have a separate value of 0xffffffff.(Christian)

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 3b505759447637dcccb50cbd98ec6f8d2a04fc463b505759447637dcccb50cbd98ec6f8d2a04fc46
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < df02642c21c984303fe34c3f7d72965792fb1a15df02642c21c984303fe34c3f7d72965792fb1a15
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < da6a85d197888067e8d38b5d22c986b5b5cab712da6a85d197888067e8d38b5d22c986b5b5cab712
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 9ee1534ecdd5b4c013064663502d7fde824d21449ee1534ecdd5b4c013064663502d7fde824d2144
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 855ae72c20310e5402b2317fc537d911e87537ef855ae72c20310e5402b2317fc537d911e87537ef
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < f8f120b3de48b8b6bdf8988a9b334c2d61c17440f8f120b3de48b8b6bdf8988a9b334c2d61c17440
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 88a9a467c548d0b3c7761b4fd54a68e70f9c094488a9a467c548d0b3c7761b4fd54a68e70f9c0944
linuxlinux_kernel< 6.6.396.6.39
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-196.2165.4.0-196.216
linuxlinux_kernel>= 0 < 5.15.0-122.1325.15.0-122.132
linuxlinux_kernel>= 0 < 6.8.0-45.456.8.0-45.45
linuxlinux_kernel>= 0 < 4.4.0-259.2934.4.0-259.293
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 6.7 < 6.9.96.9.9
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0
msrcazure_linux_3.0_arm

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.