CVE-2024-38552
Published: Jun 19, 2024
Modified: May 12, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of bounds issue in the color transformation function. The issue could occur when the index 'i' exceeds the number of transfer function points (TRANSFER_FUNC_POINTS). The fix adds a check to ensure 'i' is within bounds before accessing the transfer function points. If 'i' is out of bounds, an error message is logged and the function returns false to indicate an error. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:405 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:406 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:407 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected b629596072e5fa901c84f9e88d845a696ee32942 - < 604c506ca43fce52bb882cff9c1fdf2ec3b4029caffected b629596072e5fa901c84f9e88d845a696ee32942 - < e280ab978c81443103d7c61bdd1d8d708cf6ed6daffected b629596072e5fa901c84f9e88d845a696ee32942 - < 04bc4d1090c343025d69149ca669a27c5b9c34a7affected b629596072e5fa901c84f9e88d845a696ee32942 - < ced9c4e2289a786b8fa684d8893b7045ea53ef7eaffected b629596072e5fa901c84f9e88d845a696ee32942 - < 98b8a6bfd30d07a19cfacdf82b50f84bf3360869+4 more versions |
Linux | Linux | affected 4.16unaffected 0 - < 4.16unaffected 4.19.316 - <= 4.19.*unaffected 5.4.278 - <= 5.4.*unaffected 5.10.219 - <= 5.10.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now