CVE-2024-46694

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer. (cherry picked from commit 73dd0ad9e5dad53766ea3e631303430116f834b3)

References

https://git.kernel.org/stable/c/f6f5e39a3fe7cbdba190f42b28b40bdff03c8cf0

https://git.kernel.org/stable/c/49e1b214f3239b78967c6ddb8f8ec47ae047b051

https://git.kernel.org/stable/c/3b9a33235c773c7a3768060cf1d2cf8a9153bc37

https://git.kernel.org/stable/c/093ee72ed35c2338c87c26b6ba6f0b7789c9e14e

Details

Source: Mitre, NVD

Published: 2024-09-13

Updated: 2024-09-19

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium