CVE-2024-38552

Updated: 2024-11-23 04:27:09.559865

Description:

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of bounds issue in the color transformation function. The issue could occur when the index 'i' exceeds the number of transfer function points (TRANSFER_FUNC_POINTS). The fix adds a check to ensure 'i' is within bounds before accessing the transfer function points. If 'i' is out of bounds, an error message is logged and the function returns false to indicate an error. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:405 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:406 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:407 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1743193221 2024-09-02 17:23:01
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725872696 2024-09-09 05:23:11
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725876080 2024-09-09 12:12:58
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725871927 2024-09-09 05:23:10
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Not Vulnerable 2024-08-14 08:17:27
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Not Vulnerable 2024-08-14 08:17:27