CVE-2024-46871

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 9, 2024
Updated: Dec 14, 2024
CWE ID 129

Summary

CVE-2024-46871 is a vulnerability affecting the Linux kernel. In the drm/amd/display subsystem, a misconfiguration in the defined value for AMDGPU_DMUB_NOTIFICATION_MAX resulted in exposing an extra type in enum dmub_notification_type. This error led to potential out-of-bound access when creating arrays dmub_callback and dmub_thread_offload, thereby jeopardizing system security. The issue has been rectified by updating the Linux kernel to correct the value of AMDGPU_DMUB_NOTIFICATION_MAX.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share