CVE-2024-46818
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 129
Summary
CVE-2024-46818 is a newly identified vulnerability in the Linux kernel. This issue affects the drm/amd/display subsystem and stems from a failure to verify the validity of a gpio_id before using it as an array index. The gpio_id value of GPIO_ID_UNKNOWN (-1) is not valid for this purpose and can result in index overruns. These overruns pose a potential security risk and have been addressed by the fix implemented in this update. The vulnerability was reported by Coverity and resulted in the discovery of five separate occurrences of this issue in the codebase.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.