CVE-2024-42120: drm/amd/display: Check pipe offset before setting vblank
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check pipe offset before setting vblank
pipectx has a size of MAXPIPES so checking its index before accessing the array.
This fixes an OVERRUN issue reported by Coverity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42120?
CVE-2024-42120 is considered a medium severity vulnerability due to an OVERRUN issue in the Linux kernel.
How do I fix CVE-2024-42120?
To fix CVE-2024-42120, update to the patched versions of the Linux kernel, specifically 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.15-1.
Which systems are affected by CVE-2024-42120?
CVE-2024-42120 affects Linux kernel versions prior to the patches mentioned, particularly those utilizing AMD display drivers.
What does CVE-2024-42120 specifically address?
CVE-2024-42120 addresses an issue in the Linux kernel related to pipe context index checking, preventing array overruns.
Is there a workaround for CVE-2024-42120 if I cannot update immediately?
There are no known workarounds for CVE-2024-42120, and it is recommended to apply the security updates as soon as possible.