PT-2024-3402 · Linux · Linux Kernel

CVE-2024-26728

·

Published

2024-02-22

·

Updated

2025-01-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.5.0-asdn+
Description: The vulnerability is related to a null-pointer dereference in the Linux kernel's drm/amd/display module. This occurs when the kernel attempts to read EDID (Extended Display Identification Data) from a display device without properly checking if the required data is available. The issue arises when running the igt@kms force connector basic test in a system with DCN2.1 and an HDMI connector. This can lead to a kernel crash or potentially allow an attacker to execute arbitrary code.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the null-pointer dereference in the drm/amd/display module. Specifically, versions 6.5.0-asdn+ and later should include this fix. Ensure that all affected systems are updated to prevent potential exploitation of this vulnerability.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03674
CVE-2024-26728

Affected Products

Linux Kernel