CVE-2021-47108

MEDIUM

Linux Kernel 5.14-5.15.11 - NULL Pointer Dereference in mtk_hdmi_bridge_mode_valid

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check for CEA modes only") a check for CEA modes was added to function mtk_hdmi_bridge_mode_valid() in order to address possible issues on MT8167; moreover, with commit c91026a938c2 ("drm/mediatek: hdmi: Add optional limit on maximal HDMI mode clock") another similar check was introduced. Unfortunately though, at the time of writing, MT8173 does not provide any mtk_hdmi_conf structure and this is crashing the kernel with NULL pointer upon entering mtk_hdmi_bridge_mode_valid(), which happens as soon as a HDMI cable gets plugged in. To fix this regression, add a NULL pointer check for hdmi->conf in the said function, restoring HDMI functionality and avoiding NULL pointer kernel panics.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (8)
Linux/Linux < 5.14
Linux/Linux 41ca9caaae0bfc959b22dbcd59d88a7107707e17 - 3b8e19a0aa3933a785be9f1541afd8d398c4ec69
Linux/Linux 41ca9caaae0bfc959b22dbcd59d88a7107707e17 - 71d07ebc5000b9c1d140e99e7493b0bafa954776
Linux/Linux 5.14
Linux/Linux 5.15.12 - 5.15.*
Linux/Linux 5.16
linux/linux_kernel 5.16 rc1 (6 CPE variants)
linux/linux_kernel 5.14 - 5.15.12
Published Mar 04, 2024
Tracked Since Feb 18, 2026