CVE-2024-42310: drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
Published Aug 17, 2024
·Updated
drm/gma500: fix null pointer dereference in cdvintellvdsgetmodes
Affected Software
14 affected componentsFixes available
Linux Linux kernel>=3.3<4.19.320
Linux Linux kernel>=4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>=5.11<5.15.165
Linux Linux kernel>=5.16<6.1.103
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft azl3 kernel 6.6.43.1-7
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.47.1-1
Microsoft cbl2 kernel 5.15.167.1-1
Microsoft cbl2 kernel 5.15.164.1-1
Remediation
Event History
Aug 17, 2024
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 11, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Apr 27, 2025
Data Sourced
via Ubuntu·12:34 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42310?
CVE-2024-42310 is classified as a high-severity vulnerability due to the potential for a NULL pointer dereference in the Linux kernel.
2
How do I fix CVE-2024-42310?
To fix CVE-2024-42310, update your Linux kernel to versions 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1 or apply the relevant patches.
3
Which Linux versions are affected by CVE-2024-42310?
CVE-2024-42310 affects various Linux kernel versions including those less than or equal to 5.10.223-1 and others in the specified ranges.
4
What is the impact of CVE-2024-42310?
The impact of CVE-2024-42310 may allow attackers to cause a denial of service through a NULL pointer dereference.
5
Is CVE-2024-42310 a local or remote vulnerability?
CVE-2024-42310 is generally considered a local vulnerability as it typically requires local access to the affected system to exploit.