Executive Summary

Informations
Name CVE-2024-45015 First vendor Publication 2024-09-11
Vendor Cve Last vendor Modification 2024-09-13

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()

For cases where the crtc's connectors_changed was set without enable/active getting toggled , there is an atomic_enable() call followed by an atomic_disable() but without an atomic_mode_set().

This results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in the atomic_enable() as the dpu_encoder's connector was cleared in the atomic_disable() but not re-assigned as there was no atomic_mode_set() call.

Fix the NULL ptr access by moving the assignment for atomic_enable() and also use drm_atomic_get_new_connector_for_encoder() to get the connector from the atomic_state.

Patchwork: https://patchwork.freedesktop.org/patch/606729/

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45015

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3650

Sources (Detail)

https://git.kernel.org/stable/c/3bacf814b6a61cc683c68465f175ebd938f09c52
https://git.kernel.org/stable/c/3fb61718bcbe309279205d1cc275a6435611dc77
https://git.kernel.org/stable/c/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Date Informations
2025-01-08 03:04:59
  • Multiple Updates
2025-01-07 03:04:32
  • Multiple Updates
2024-12-25 03:03:11
  • Multiple Updates
2024-12-12 03:06:07
  • Multiple Updates
2024-11-23 03:03:07
  • Multiple Updates
2024-11-22 03:01:18
  • Multiple Updates
2024-11-20 02:59:38
  • Multiple Updates
2024-11-14 02:59:56
  • Multiple Updates
2024-11-09 02:59:56
  • Multiple Updates
2024-10-26 02:57:19
  • Multiple Updates
2024-10-25 02:59:12
  • Multiple Updates
2024-10-23 02:58:24
  • Multiple Updates
2024-10-03 02:53:35
  • Multiple Updates
2024-10-02 02:51:59
  • Multiple Updates
2024-09-14 21:29:47
  • Multiple Updates
2024-09-13 21:28:03
  • Multiple Updates
2024-09-11 21:27:24
  • First insertion