CVE-2024-49894

HIGH EPSS 24.4%
Published Oct 21, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Oct 21, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could occur when the index 'i' exceeds the number of transfer function points (TRANSFER_FUNC_POINTS). The fix adds a check to ensure 'i' is within bounds before accessing the transfer function points. If 'i' is out of bounds the function returns false to indicate an error. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:594 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:595 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:596 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
24.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-129

Affected Products 12

VendorProductVersionRange
siemenssimatic_s7-1500_tm_mfp_firmware1.1any
siemenssimatic_s7-1500_tm_mfp*any
debiandebian_linux11.0any
linuxlinux_kernel*≥4.15  –  <4.19.323
linuxlinux_kernel*≥4.20  –  <5.4.285
linuxlinux_kernel*≥5.5  –  <5.10.227
linuxlinux_kernel*≥5.11  –  <5.15.168
linuxlinux_kernel*≥5.16  –  <6.1.113
linuxlinux_kernel*≥6.2  –  <6.6.55
linuxlinux_kernel*≥6.7  –  <6.10.14
linuxlinux_kernel*≥6.11  –  <6.11.3
siemenssinec_os* <3.2

References 13

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-265688.html
    Third Party Advisory
  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-355557.html
    Third Party Advisory
  • git.kernel.org https://git.kernel.org/stable/c/07078fa5d589a7fbce8f81ea8acf7aa0021ab38e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/122e3a7a8c7bcbe3aacddd6103f67f9f36bed473
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2495c8e272d84685403506833a664fad932e453a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f5da549535be8ccd2ab7c9abac8562ad370b181
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3dfa878257a7e98830b3009ca5831a01d8f85fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b7e99058eb2e86aabd7a10761e76cae33d22b49f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c130a3c09e3746c1a09ce26c20d21d449d039b1d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c6979719012a90e5b8e3bc31725fbfdd0b9b2b79
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f5f6d90087131812c1e4b9d3103f400f1624396d
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
    Mailing ListThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/07078fa5d589a7fbce8f81ea8acf7aa0021ab38e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/122e3a7a8c7bcbe3aacddd6103f67f9f36bed473
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2495c8e272d84685403506833a664fad932e453a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f5da549535be8ccd2ab7c9abac8562ad370b181
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3dfa878257a7e98830b3009ca5831a01d8f85fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b7e99058eb2e86aabd7a10761e76cae33d22b49f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c130a3c09e3746c1a09ce26c20d21d449d039b1d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c6979719012a90e5b8e3bc31725fbfdd0b9b2b79
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f5f6d90087131812c1e4b9d3103f400f1624396d
    Patch