CVE-2024-44977

HIGH EPSS 16.6%
Published Sep 4, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Sep 4, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Validate TA binary size Add TA binary size validation to avoid OOB write. (cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
16.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 8

VendorProductVersionRange
debiandebian_linux11.0any
linuxlinux_kernel*≥5.19  –  <6.1.107
linuxlinux_kernel*>6.2  –  <6.6.48
linuxlinux_kernel*>6.7  –  <6.10.7
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f
    Patch