cbcvebase.
CVE-2024-46813
published 2024-09-27

CVE-2024-46813: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check link_index before accessing dc->links[] [WHY & HOW] dc->links[] has…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check link_index before accessing dc->links[] [WHY & HOW] dc->links[] has max size of MAX_LINKS and NULL is return when trying to access with out-of-bound index. This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.9-1 (forky)linux 6.10.9-1 (forky)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 032c5407a608ac3b2a98bf4fbda27d12c20c5887032c5407a608ac3b2a98bf4fbda27d12c20c5887
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < ac04759b4a002969cf0f1384f1b8bb2001cfa782ac04759b4a002969cf0f1384f1b8bb2001cfa782
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 8aa2864044b9d13e95fe224f32e808afbf79ecdf8aa2864044b9d13e95fe224f32e808afbf79ecdf
linuxlinux_kernel< 6.6.876.6.87
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.7 < 6.10.96.10.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.