CVE-2024-49917: drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn30_init_hw
drm/amd/display: Add NULL check for clkmgr and clkmgr->funcs in dcn30inithw
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.64.2-9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49917?
CVE-2024-49917 has a medium severity rating due to the potential for null pointer dereferences in the Linux kernel.
How do I fix CVE-2024-49917?
To fix CVE-2024-49917, update the Linux kernel to version 6.10.14 or later, or apply one of the specific patches.
Which versions of the Linux kernel are affected by CVE-2024-49917?
CVE-2024-49917 affects Linux kernel versions below 6.10.14 and between 6.11 and 6.11.3.
Can CVE-2024-49917 lead to system instability?
Yes, CVE-2024-49917 can potentially lead to system instability by causing null pointer dereference issues.
Is CVE-2024-49917 related to the AMD graphics driver?
Yes, CVE-2024-49917 specifically involves the AMD display driver functionality in the Linux kernel.