SB2024062455 - Buffer overflow in Linux kernel gpu drm driver
Published: June 24, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2021-47444)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the connector_bad_edid() function in drivers/gpu/drm/drm_edid.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/a7b45024f66f9ec769e8dbb1a51ae83cd05929c7
- https://git.kernel.org/stable/c/09f3946bb452918dbfb1982add56f9ffaae393dc
- https://git.kernel.org/stable/c/97794170b696856483f74b47bfb6049780d2d3a0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.75
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15