CVE-2024-42228

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001. V2: To really improve the handling we would actually need to have a separate value of 0xffffffff.(Christian)
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

04 Sep 2024, 12:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/3b505759447637dcccb50cbd98ec6f8d2a04fc46 -
  • () https://git.kernel.org/stable/c/9ee1534ecdd5b4c013064663502d7fde824d2144 -
  • () https://git.kernel.org/stable/c/d35cf41c8eb5d9fe95b21ae6ee2910f9ba4878e8 -
  • () https://git.kernel.org/stable/c/da6a85d197888067e8d38b5d22c986b5b5cab712 -
  • () https://git.kernel.org/stable/c/df02642c21c984303fe34c3f7d72965792fb1a15 -

30 Jul 2024, 20:12

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef - () https://git.kernel.org/stable/c/855ae72c20310e5402b2317fc537d911e87537ef - Patch
References () https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944 - () https://git.kernel.org/stable/c/88a9a467c548d0b3c7761b4fd54a68e70f9c0944 - Patch
References () https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440 - () https://git.kernel.org/stable/c/f8f120b3de48b8b6bdf8988a9b334c2d61c17440 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CWE CWE-908
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: drm/amdgpu: uso del valor no inicializado *size al llamar a amdgpu_vce_cs_reloc Inicialice el tamaño antes de llamar a amdgpu_vce_cs_reloc, como en el caso 0x03000001. V2: Para mejorar realmente el manejo, necesitaríamos tener un valor separado de 0xffffffff. (Christian)

30 Jul 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 08:15

Updated : 2024-09-04 12:15


NVD link : CVE-2024-42228

Mitre link : CVE-2024-42228

CVE.ORG link : CVE-2024-42228


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-908

Use of Uninitialized Resource