Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Atom Integrated System Info v2_2 for DCN35 New request from KMD/VBIOS in order to support new UMA carveout model. This fixes a null dereference from accessing Ctx->dc_bios->integrated_info while it was NULL. DAL parses through the BIOS and extracts the necessary integrated_info but was missing a case for the new BIOS version 2.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.15.159 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/02f5300f6827206f6e48a77f51e6264993695e5cPatch
- https://git.kernel.org/stable/c/3c7013a87124bab54216d9b99f77e8b6de6fbc1aPatch
- https://git.kernel.org/stable/c/7e3030774431eb093165a31baff040d35446fb8bPatch
- https://git.kernel.org/stable/c/9a35d205f466501dcfe5625ca313d944d0ac2d60Patch
- https://git.kernel.org/stable/c/c2797ec16d9072327e7578d09ee05bcab52fffd0Patch
- https://git.kernel.org/stable/c/02f5300f6827206f6e48a77f51e6264993695e5cPatch
- https://git.kernel.org/stable/c/3c7013a87124bab54216d9b99f77e8b6de6fbc1aPatch
- https://git.kernel.org/stable/c/7e3030774431eb093165a31baff040d35446fb8bPatch
- https://git.kernel.org/stable/c/9a35d205f466501dcfe5625ca313d944d0ac2d60Patch
- https://git.kernel.org/stable/c/c2797ec16d9072327e7578d09ee05bcab52fffd0Patch
FAQ
What is CVE-2024-36897?
CVE-2024-36897 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Atom Integrated System Info v2_2 for DCN35 New request from KMD/VBIOS in order to support new UMA carveout model....
How severe is CVE-2024-36897?
CVE-2024-36897 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36897?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.