NULL pointer dereference in Linux kernel - CVE-2024-43904
Published: August 26, 2024 / Updated: May 12, 2025
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the dcn30_apply_idle_power_optimizations() function in drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c. A local user can perform a denial of service (DoS) attack.
How to mitigate CVE-2024-43904
Sources
- https://git.kernel.org/stable/c/16a8a2a839d19c4cf7253642b493ffb8eee1d857
- https://git.kernel.org/stable/c/15c2990e0f0108b9c3752d7072a97d45d4283aea
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.181
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.116
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.60