cbcvebase.
CVE-2024-46871
published 2024-10-09

CVE-2024-46871: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX [Why & How] It…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
12.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX [Why & How] It actually exposes '6' types in enum dmub_notification_type. Not 5. Using smaller number to create array dmub_callback & dmub_thread_offload has potential to access item out of array bound. Fix it.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < e1896f381d27466c26cb44b4450eae05cd59dfd0e1896f381d27466c26cb44b4450eae05cd59dfd0
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 9f404b0bc2df3880758fb3c3bc7496f596f347d79f404b0bc2df3880758fb3c3bc7496f596f347d7
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 800a5ab673c4a61ca220cce177386723d91bdb37800a5ab673c4a61ca220cce177386723d91bdb37
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < c592b6355b9b57b8e59fc5978ce1e14f64488a98c592b6355b9b57b8e59fc5978ce1e14f64488a98
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < ad28d7c3d989fc5689581664653879d664da76f0ad28d7c3d989fc5689581664653879d664da76f0
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.15 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1096.1.109
linuxlinux_kernel>= 6.2 < 6.6.506.6.50
linuxlinux_kernel>= 6.7 < 6.10.96.10.9
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.