cbcvebase.
CVE-2024-49907
published 2024-10-21

CVE-2024-49907: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before using dc->clk_mgr [WHY & HOW] dc->clk_mgr is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before using dc->clk_mgr [WHY & HOW] dc->clk_mgr is null checked previously in the same function, indicating it might be null. Passing "dc" to "dc->hwss.apply_idle_power_optimizations", which dereferences null "dc->clk_mgr". (The function pointer resolves to "dcn35_apply_idle_power_optimizations".) This fixes 1 FORWARD_NULL issue reported by Coverity.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 8d54001f8dccd56146973f23f3ab2ba037a212518d54001f8dccd56146973f23f3ab2ba037a21251
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a545a9403e04c6e17fdc04a26a61d9feebbba106a545a9403e04c6e17fdc04a26a61d9feebbba106
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a2773e0a4b79e7a6463abdffaf8cc4f24428ba18a2773e0a4b79e7a6463abdffaf8cc4f24428ba18
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 9641bc4adf8446034e490ed543ae7e9833cfbdf59641bc4adf8446034e490ed543ae7e9833cfbdf5
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 3f7e533c10db3d0158709a99e2129ff63add6bcd3f7e533c10db3d0158709a99e2129ff63add6bcd
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 5ba3fbf75b243b2863a8be9e7c393e003d3b88f35ba3fbf75b243b2863a8be9e7c393e003d3b88f3
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 95d9e0803e51d5a24276b7643b244c7477daf46395d9e0803e51d5a24276b7643b244c7477daf463
linuxlinux_kernel< 5.10.2275.10.227
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.36.11.3
linuxlinux_kernel>= 6.2 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.10.146.10.14
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.