Resource management error in Linux kernel - CVE-2024-46820

 

Resource management error in Linux kernel - CVE-2024-46820

Published: September 30, 2024 / Updated: May 12, 2025


Vulnerability identifier: #VU97826
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-46820
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the vcn_v5_0_0_hw_fini(), vcn_v5_0_0_set_powergating_state() and vcn_v5_0_0_process_interrupt() functions in drivers/gpu/drm/amd/amdgpu/vcn_v5_0_0.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
IBM API Connect
Red Hat OpenShift Dev Spaces
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data

How to mitigate CVE-2024-46820

Install update from vendor's website.

Linux kernel - addressed in versions 6.10.9, 6.11
IBM API Connect - update to 10.0.8.5
Red Hat OpenShift Dev Spaces - update to 3.21.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
DB2 on Cloud Pak for Data - update to 4.8.8

External References

Related Security Bulletins