cbcvebase.
CVE-2024-46694
published 2024-09-13

CVE-2024-46694: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid using null object of framebuffer Instead of using state->fb->obj[0]…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer. (cherry picked from commit 73dd0ad9e5dad53766ea3e631303430116f834b3)

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 5d945cbcd4b16a29d6470a80dfb19738f9a4319f < 093ee72ed35c2338c87c26b6ba6f0b7789c9e14e093ee72ed35c2338c87c26b6ba6f0b7789c9e14e
linuxlinux>= 5d945cbcd4b16a29d6470a80dfb19738f9a4319f < f6f5e39a3fe7cbdba190f42b28b40bdff03c8cf0f6f5e39a3fe7cbdba190f42b28b40bdff03c8cf0
linuxlinux>= 5d945cbcd4b16a29d6470a80dfb19738f9a4319f < 49e1b214f3239b78967c6ddb8f8ec47ae047b05149e1b214f3239b78967c6ddb8f8ec47ae047b051
linuxlinux>= 5d945cbcd4b16a29d6470a80dfb19738f9a4319f < 3b9a33235c773c7a3768060cf1d2cf8a9153bc373b9a33235c773c7a3768060cf1d2cf8a9153bc37
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.0 < 6.1.1086.1.108
linuxlinux_kernel>= 6.2 < 6.6.496.6.49
linuxlinux_kernel>= 6.7 < 6.10.86.10.8
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.