Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46724

Опубликовано: 18 сент. 2024
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds read error

A flaw was found in the drm/amdgpu component of the Linux kernel. An improper range check of the fb_channel_number could allow a local attacker to perform an out-of-bounds read. This could lead to information disclosure or a denial of service (DoS).

Меры по смягчению последствий

To mitigate this issue, prevent the amdgpu kernel module from loading. This can be achieved by creating a modprobe configuration file.

  1. Create a file named /etc/modprobe.d/disable-amdgpu.conf with the following content:
blacklist amdgpu install amdgpu /bin/true
  1. Regenerate the initramfs to apply the changes:
dracut -f -v
  1. Reboot the system for the changes to take effect. Warning: Blacklisting the amdgpu module will disable AMD graphics functionality, potentially impacting system display and performance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 9kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelFixedRHSA-2025:696613.05.2025
Red Hat Enterprise Linux 9kernelFixedRHSA-2025:696613.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2313055kernel: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number

EPSS

Процентиль: 16%
0.00242
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds read error

CVSS3: 7.1
nvd
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds read error

CVSS3: 7.1
msrc
7 месяцев назад

drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number

CVSS3: 7.1
debian
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: d ...

CVSS3: 7.1
github
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds read error

EPSS

Процентиль: 16%
0.00242
Низкий

7.1 High

CVSS3