CVE-2024-27029: drm/amdgpu: fix mmhub client id out-of-bounds access
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix mmhub client id out-of-bounds access
Properly handle cid 0x140.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Configuration
Update the Linux kernel so that drm/amdgpu correctly handles mmhub client id cid 0x140 and prevents out-of-bounds access.
Linux kernel (drm/amdgpu) mmhub client id handling = Properly handle cid 0x140
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27029?
CVE-2024-27029 is classified with a medium severity level due to the potential for unauthorized access through mmhub client id out-of-bounds access.
How do I fix CVE-2024-27029?
To fix CVE-2024-27029, update your Linux kernel to the appropriate patched version specified in your distribution's security advisories.
Which versions of the Linux kernel are affected by CVE-2024-27029?
CVE-2024-27029 affects Linux kernel versions from 6.7 to 6.7.11 and 6.8 to 6.8.2.
What systems are vulnerable to CVE-2024-27029?
Systems running affected versions of the Linux kernel and using the amdgpu driver may be vulnerable to CVE-2024-27029.
Does CVE-2024-27029 have any known exploits?
As of now, there are no public reports of known exploits specifically targeting CVE-2024-27029.