CVE-2024-41061

HIGH

Linux Kernel 6.7-6.9.11 - Out-of-Bounds Array Index in dml2_calculate_rq_and_dlg_params

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dml2/FCLKChangeSupport [Why] Potential out of bounds access in dml2_calculate_rq_and_dlg_params() because the value of out_lowest_state_idx used as an index for FCLKChangeSupport array can be greater than 1. [How] Currently dml2 core specifies identical values for all FCLKChangeSupport elements. Always use index 0 in the condition to avoid out of bounds access.

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-129
Status published
Products (8)
linux/Kernel 6.7.0 - 6.9.11linux
Linux/Linux < 6.7
Linux/Linux 6.10
Linux/Linux 6.7
Linux/Linux 6.9.11 - 6.9.*
Linux/Linux 7966f319c66d9468623c6a6a017ecbc0dd79be75 - 0ad4b4a2f6357c45fbe444ead1a929a0b4017d03
Linux/Linux 7966f319c66d9468623c6a6a017ecbc0dd79be75 - 94166fe12543fbef122ca2d093e794ea41073a85
linux/linux_kernel 6.7 - 6.9.11
Published Jul 29, 2024
Tracked Since Feb 18, 2026