drm/amd/pm: Vangogh: Fix kernel memory out of bounds write
CVE-2024-50221

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 November 2024

What is CVE-2024-50221?

A vulnerability has been identified in the AMDGPU driver within the Linux kernel, specifically in the Vangogh GPU metrics table initialization. The issue arises from an insufficient allocation size for the GPU metrics table during the initialization process, leading to potential out of bounds writes. When the GPU metrics table is populated with a larger block of memory than allocated, this can cause undefined behavior, memory corruption, or stability issues within the system. The root cause is linked to the addition of GPU metrics tables for version v2_4 components, which were not factored into the required table size. The proposed fix involves adjusting the table allocation to accommodate the necessary memory for initialization, ensuring proper function without inducing memory-related errors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 41cec40bc9baba83d36a0718ea94bfe63189274a

Linux 41cec40bc9baba83d36a0718ea94bfe63189274a

Linux 41cec40bc9baba83d36a0718ea94bfe63189274a < 4aa923a6e6406b43566ef6ac35a3d9a3197fa3e8

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.