CVE-2024-38548
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference In cdns_mhdp_atomic_enable(), the return value of drm_mode_duplicate() is assigned to mhdp_state->current_mode, and…
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference In cdns_mhdp_atomic_enable(), the return value of drm_mode_duplicate() is assigned to mhdp_state->current_mode, and there is a dereference of it in drm_mode_set_name(), which will lead to a NULL pointer dereference on failure of drm_mode_duplicate(). Fix this bug add a check of mhdp_state->current_mode.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/32fb2ef124c3301656ac6c789a2ef35ef69a66daPatch
- https://git.kernel.org/stable/c/47889711da20be9b43e1e136e5cb68df37cbcc79Patch
- https://git.kernel.org/stable/c/85d1a27402f81f2e04b0e67d20f749c2a14edbb3Patch
- https://git.kernel.org/stable/c/89788cd9824c28ffcdea40232c458233353d1896Patch
- https://git.kernel.org/stable/c/935a92a1c400285545198ca2800a4c6c519c650aPatch
- https://git.kernel.org/stable/c/ca53b7efd4ba6ae92fd2b3085cb099c745e96965Patch
- https://git.kernel.org/stable/c/dcf53e6103b26e7458be71491d0641f49fbd5840Patch
- https://git.kernel.org/stable/c/32fb2ef124c3301656ac6c789a2ef35ef69a66daPatch
- https://git.kernel.org/stable/c/47889711da20be9b43e1e136e5cb68df37cbcc79Patch
- https://git.kernel.org/stable/c/85d1a27402f81f2e04b0e67d20f749c2a14edbb3Patch
- https://git.kernel.org/stable/c/89788cd9824c28ffcdea40232c458233353d1896Patch
- https://git.kernel.org/stable/c/935a92a1c400285545198ca2800a4c6c519c650aPatch
- https://git.kernel.org/stable/c/ca53b7efd4ba6ae92fd2b3085cb099c745e96965Patch
- https://git.kernel.org/stable/c/dcf53e6103b26e7458be71491d0641f49fbd5840Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.