7.8

CVE-2021-47489

drm/amdgpu: Fix even more out of bound writes from debugfs

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix even more out of bound writes from debugfs

CVE-2021-42327 was fixed by:

commit f23750b5b3d98653b31d4469592935ef6364ad67
Author: Thelford Williams <tdwilliamsiv@gmail.com>
Date:   Wed Oct 13 16:04:13 2021 -0400

    drm/amdgpu: fix out of bounds write

but amdgpu_dm_debugfs.c contains more of the same issue so fix the
remaining ones.

v2:
	* Add missing fix in dp_max_bpc_write (Harry Wentland)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 11.0
Linux ≫ Linux Kernel Version >= 5.10 < 5.10.236
Linux ≫ Linux Kernel Version >= 5.11 < 5.14.16
Linux ≫ Linux Kernel Version 5.15 Update rc1
Linux ≫ Linux Kernel Version 5.15 Update rc2
Linux ≫ Linux Kernel Version 5.15 Update rc3
Linux ≫ Linux Kernel Version 5.15 Update rc4
Linux ≫ Linux Kernel Version 5.15 Update rc5
Linux ≫ Linux Kernel Version 5.15 Update rc6
Linux ≫ Linux Kernel Version 5.15 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.12
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/3f4e54bd312d3dafb59daf2b97ffa08abebe60f5
Patch
https://git.kernel.org/stable/c/9eb4bdd554fc31a5ef6bf645a20ff21618ce45a9
Patch
https://git.kernel.org/stable/c/1336b886b162fdc84708096ea152a61c0e1fc09c
Patch
https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
Third Party Advisory
Mailing List