cbcvebase.
CVE-2024-43904
published 2024-08-26

CVE-2024-43904: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing This commit…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing This commit adds null checks for the 'stream' and 'plane' variables in the dcn30_apply_idle_power_optimizations function. These variables were previously assumed to be null at line 922, but they were used later in the code without checking if they were null. This could potentially lead to a null pointer dereference, which would cause a crash. The null checks ensure that 'stream' and 'plane' are not null before they are used, preventing potential crashes. Fixes the below static smatch checker: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:938 dcn30_apply_idle_power_optimizations() error: we previously assumed 'stream' could be null (see line 922) drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:940 dcn30_apply_idle_power_optimizations() error: we previously assumed 'plane' could be null (see line 922)

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < fcf9d6a9f30ea414b6b84a6e901cebd44e146847fcf9d6a9f30ea414b6b84a6e901cebd44e146847
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 5e84eda48ffb2363437db44bbd0235594f8a58f95e84eda48ffb2363437db44bbd0235594f8a58f9
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 10c20d79d59cadfe572480d98cec271a89ffb02410c20d79d59cadfe572480d98cec271a89ffb024
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 16a8a2a839d19c4cf7253642b493ffb8eee1d85716a8a2a839d19c4cf7253642b493ffb8eee1d857
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 15c2990e0f0108b9c3752d7072a97d45d4283aea15c2990e0f0108b9c3752d7072a97d45d4283aea
linuxlinux_kernel< 6.10.56.10.5
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.