CVE-2024-49969
Published: Oct 21, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in DCN30 color transformation This commit addresses a potential index out of bounds issue in the `cm3_helper_translate_curve_to_hw_format` function in the DCN30 color management module. The issue could occur when the index 'i' exceeds the number of transfer function points (TRANSFER_FUNC_POINTS). The fix adds a check to ensure 'i' is within bounds before accessing the transfer function points. If 'i' is out of bounds, the function returns false to indicate an error. drivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:180 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:181 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max drivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:182 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 03f54d7d3448dc1668568d1adb69b43c1d1dc79f - < 7ab69af56a23859b647dee69fa1052c689343621affected 03f54d7d3448dc1668568d1adb69b43c1d1dc79f - < c13f9c62015c56a938304cef6d507227ea3e0039affected 03f54d7d3448dc1668568d1adb69b43c1d1dc79f - < 0f1e222a4b41d77c442901d166fbdca967af0d86affected 03f54d7d3448dc1668568d1adb69b43c1d1dc79f - < 929506d5671419cffd8d01e9a7f5eae53682a838affected 03f54d7d3448dc1668568d1adb69b43c1d1dc79f - < 578422ddae3d13362b64e77ef9bab98780641631+2 more versions |
Linux | Linux | affected 5.9unaffected 0 - < 5.9unaffected 5.10.227 - <= 5.10.*unaffected 5.15.168 - <= 5.15.*unaffected 6.1.113 - <= 6.1.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now