CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Stop amdgpudm initialize when stream nums greater than 6
[Why] Coverity reports OVERRUN warning. Should abort amdgpudm initialize.
[How] Return failure to amdgpudminit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46817?
CVE-2024-46817 has been classified as a moderate severity vulnerability due to its impact on the Linux kernel's amdgpu_dm initialization process.
How do I fix CVE-2024-46817?
To fix CVE-2024-46817, update your Linux kernel to a version that includes the resolution for this vulnerability, such as 5.10.226-1 or later.
Which versions of the Linux kernel are affected by CVE-2024-46817?
CVE-2024-46817 affects Linux kernel versions from 5.4 up to 6.10.9, specifically versions that do not have the patch applied.
Is there a specific package for CVE-2024-46817 resolution?
Yes, users can apply the patch for CVE-2024-46817 through specific Debian packages like linux-6.1 version 6.1.119-1~deb11u1.
What components are impacted by CVE-2024-46817?
CVE-2024-46817 mainly impacts the amdgpu_dm component of the Linux kernel during the initialization phase.