CVE-2024-49971 Information

Description

In the Linux kernel the following vulnerability has been resolved:

drm/amd/display: Increase array size of dummy_boolean

[WHY] dml2_core_shared_mode_support and dml_core_mode_support access the third element of dummy_boolean i.e. hw_debug5 = &s->dummy_boolean[2] when dummy_boolean has size of 2. Any assignment to hw_debug5 causes an OVERRUN.

[HOW] Increase dummy_boolean’s array size to 3.

This fixes 2 OVERRUN issues reported by Coverity.

Reference

https://git.kernel.org/stable/c/e9e48b7bb9cf3b78f0305ef0144aaf61da0a83d8 https://git.kernel.org/stable/c/6d64d39486197083497a01b39e23f2f8474b35d3

Share on: