Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-53133— drm/amd/display: Handle dml allocation failure to avoid crash

CVSS 7.8 · High EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinuxabd26a3252cbd1a3ae4e46d37596d176fe50b41a< 874ff59cde8fc525112dda26b501a1bac17dde9faffected
abd26a3252cbd1a3ae4e46d37596d176fe50b41a< 6825cb07b79ffeb1d90ffaa7a1227462cdca34aeaffected
2064f7529dfe0305d6fafda77fdf66701d428db5affected
6.7.12< 6.8affected
6.8affected
< 6.8unaffected
6.11.10≤ 6.11.*unaffected
6.12≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-53133

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/amd/display: Handle dml allocation failure to avoid crash
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml allocation fails for any reason, the current state's dml contexts would no longer be valid. Then subsequent calls dc_state_copy_internal would shallow copy invalid memory and if the new state was released, a double free would occur. [How] Reset dml pointers in new_state to NULL and avoid invalid pointer (cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于drm/amd/display驱动中未能正确处理dml分配失败,可能导致崩溃的问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux abd26a3252cbd1a3ae4e46d37596d176fe50b41a ~ 874ff59cde8fc525112dda26b501a1bac17dde9f -
LinuxLinux 6.8 -

II. Public POCs for CVE-2024-53133

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-53133

登录查看更多情报信息。

Patches & Fixes for CVE-2024-53133 (2)

Same Patch Batch · Linux · 2024-12-04 · 16 CVEs total

CVE-2024-531389.8 CRITICALnet/mlx5e: kTLS, Fix incorrect page refcounting
CVE-2024-531358.8 HIGHKVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
CVE-2024-531257.8 HIGHbpf: sync_linked_regs() must preserve subreg_def
CVE-2024-531277.8 HIGHRevert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
CVE-2024-531397.8 HIGHsctp: fix possible UAF in sctp_v6_available()
CVE-2024-531407.8 HIGHnetlink: terminate outstanding dump on socket close
CVE-2024-531367.5 HIGHmm: revert "mm: shmem: fix data-race in shmem_getattr()"
CVE-2024-531267.1 HIGHvdpa: solidrun: Fix UB bug with devres
CVE-2024-53128sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers
CVE-2024-53129drm/rockchip: vop: Fix a dereferenced before check warning
CVE-2024-53130nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
CVE-2024-53131nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
CVE-2024-53132drm/xe/oa: Fix "Missing outer runtime PM protection" warning
CVE-2024-53134pmdomain: imx93-blk-ctrl: correct remove path
CVE-2024-53137ARM: fix cacheflush with PAN

IV. Related Vulnerabilities

V. Comments for CVE-2024-53133

No comments yet


Leave a comment