cbcvebase.
CVE-2024-56616
published 2024-12-27

CVE-2024-56616: In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix MST sideband message body length check Fix the MST sideband message body…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
12.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix MST sideband message body length check Fix the MST sideband message body length check, which must be at least 1 byte accounting for the message body CRC (aka message data CRC) at the end of the message. This fixes a case where an MST branch device returns a header with a correct header CRC (indicating a correctly received body length), with the body length being incorrectly set to 0. This will later lead to a memory corruption in drm_dp_sideband_append_payload() and the following errors in dmesg: UBSAN: array-index-out-of-bounds in drivers/gpu/drm/display/drm_dp_mst_topology.c:786:25 index -1 is out of range for type 'u8 [48]' Call Trace: drm_dp_sideband_append_payload+0x33d/0x350 [drm_display_helper] drm_dp_get_one_sb_msg+0x3ce/0x5f0 [drm_display_helper] drm_dp_mst_hpd_irq_handle_event+0xc8/0x1580 [drm_display_helper] memcpy: detected field-spanning write (size 18446744073709551615) of single field "&msg->msg[msg->curlen]" at drivers/gpu/drm/display/drm_dp_mst_topology.c:791 (size 256) Call Trace: drm_dp_sideband_append_payload+0x324/0x350 [drm_display_helper] drm_dp_get_one_sb_msg+0x3ce/0x5f0 [drm_display_helper] drm_dp_mst_hpd_irq_handle_event+0xc8/0x1580 [drm_display_helper]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < 109f91d8b9335b0f3714ef9920eae5a8b21d56af109f91d8b9335b0f3714ef9920eae5a8b21d56af
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < 70e7166612f4e6da8d7d0305c47c465d88d037e570e7166612f4e6da8d7d0305c47c465d88d037e5
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < 780fa184d4dc38ad6c4fded345ab8f9be7a63e96780fa184d4dc38ad6c4fded345ab8f9be7a63e96
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < c58947a8d4a500902597ee1dbadf0518d7ff8801c58947a8d4a500902597ee1dbadf0518d7ff8801
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < 1fc1f32c4a3421b9d803f18ec3ef49db2fb5d5ef1fc1f32c4a3421b9d803f18ec3ef49db2fb5d5ef
linuxlinux>= ad7f8a1f9ced7f049f9b66d588723f243a7034cd < bd2fccac61b40eaf08d9546acc9fef958bfe4763bd2fccac61b40eaf08d9546acc9fef958bfe4763
linuxlinux_kernel< 5.10.2335.10.233
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.11 < 5.15.1765.15.176
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.