CVE-2024-49990
published 2024-10-21CVE-2024-49990: In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when checked…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hdcp: Check GSC structure validity
Sometimes xe_gsc is not initialized when checked at HDCP capability
check. Add gsc structure check to avoid null pointer error.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.11.4-1 (forky) | linux 6.11.4-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= dd08ebf6c3525a7ea2186e636df064ea47281987 < c940627857eedca8407b84b40ceb4252b100d291 | c940627857eedca8407b84b40ceb4252b100d291 |
| linux | linux | >= dd08ebf6c3525a7ea2186e636df064ea47281987 < 7266a424b1e502745170322e3c27f697d12de627 | 7266a424b1e502745170322e3c27f697d12de627 |
| linux | linux | >= dd08ebf6c3525a7ea2186e636df064ea47281987 < b4224f6bae3801d589f815672ec62800a1501b0d | b4224f6bae3801d589f815672ec62800a1501b0d |
| linux | linux_kernel | < 6.10.14 | 6.10.14 |
| linux | linux_kernel | >= 0 < 6.11.4-1 | 6.11.4-1 |
| linux | linux_kernel | >= 0 < 6.11.4-1 | 6.11.4-1 |
| linux | linux_kernel | >= 6.11 < 6.11.3 | 6.11.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jhx-gr45-29p7: In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hdcp: Check GSC structure validity
Sometimes xe_gsc is not initialized wh
ghsa_unreviewed·2024-10-21
CVE-2024-49990 [MEDIUM] CWE-908 GHSA-9jhx-gr45-29p7: In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hdcp: Check GSC structure validity
Sometimes xe_gsc is not initialized wh
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hdcp: Check GSC structure validity
Sometimes xe_gsc is not initialized when checked at HDCP capability
check. Add gsc structure check to avoid null pointer error.
OSV
CVE-2024-49990: In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when
osv·2024-10-21·CVSS 5.5
CVE-2024-49990 [MEDIUM] CVE-2024-49990: In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when checked at HDCP capability check. Add gsc structure check to avoid null pointer error.
Red Hat
kernel: drm/xe/hdcp: Check GSC structure validity
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2024-49990 [MEDIUM] CWE-908 kernel: drm/xe/hdcp: Check GSC structure validity
kernel: drm/xe/hdcp: Check GSC structure validity
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hdcp: Check GSC structure validity
Sometimes xe_gsc is not initialized when checked at HDCP capability
check. Add gsc structure check to avoid null pointer error.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2024-49990: linux - In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp...
vendor_debian·2024·CVSS 5.5
CVE-2024-49990 [MEDIUM] CVE-2024-49990: linux - In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp...
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when checked at HDCP capability check. Add gsc structure check to avoid null pointer error.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.11.4-1)
sid: resolved (fixed in 6.11.4-1)
trixie: resolved (fixed in 6.11.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-21
Published