CVE-2024-26662: drm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()'
drm/amd/display: Fix 'panelcntl' could be null in 'dcn21setbacklightlevel()'
Other sources
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix 'panelcntl' could be null in 'dcn21setbacklightlevel()'
The Linux kernel CVE team has assigned CVE-2024-26662 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024040223-CVE-2024-26662-863c@gregkh/T
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26662?
The severity of CVE-2024-26662 is considered to be moderate due to the potential for null pointer dereference that could lead to denial of service.
How do I fix CVE-2024-26662?
To fix CVE-2024-26662, upgrade the Linux kernel to version 6.6.17, 6.7.5, 6.8, or the specific Debian kernel versions mentioned.
What does CVE-2024-26662 affect?
CVE-2024-26662 specifically affects the Linux kernel in the context of the AMD display driver and its handling of the 'panel_cntl' structure.
Is CVE-2024-26662 applicable to all Linux distributions?
CVE-2024-26662 is particularly noted for Red Hat and Debian systems, where specific kernel versions are mentioned as vulnerable.
What kind of exploitation does CVE-2024-26662 allow?
CVE-2024-26662 could potentially be exploited to trigger a system crash through a null pointer dereference in the display control.