CVE-2024-26938

MEDIUM

Linux Kernel < 6.1.84, 6.5.0-6.6.24, 6.7.0-6.7.12, 6.8.0-6.8.3 - DoS via Null Pointer Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() If we have no VBT, or the VBT didn't declare the encoder in question, we won't have the 'devdata' for the encoder. Instead of oopsing just bail early. We won't be able to tell whether the port is DP++ or not, but so be it. (cherry picked from commit 26410896206342c8a80d2b027923e9ee7d33b733)

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel 6.5.0 - 6.6.24linux
linux/Kernel 6.7.0 - 6.7.12linux
linux/Kernel 6.8.0 - 6.8.3linux
Linux/Linux < 6.5
Linux/Linux 2bea1d7c594dd0643db23a8131c689384d0e5d8c - 32e39bab59934bfd3f37097d4dd85ac5eb0fd549
Linux/Linux 2bea1d7c594dd0643db23a8131c689384d0e5d8c - 94cf2fb6feccd625e5b4e23e1b70f39a206f82ac
Linux/Linux 2bea1d7c594dd0643db23a8131c689384d0e5d8c - a891add409e3bc381f4f68c2ce9d953f1865cb1f
Linux/Linux 2bea1d7c594dd0643db23a8131c689384d0e5d8c - f4bbac954d8f9ab214ea1d4f385de4fa6bd92dd0
Linux/Linux 6.5
Linux/Linux 6.6.24 - 6.6.*
... and 5 more
Published May 01, 2024
Tracked Since Feb 18, 2026