Lucene search

K
redhatcveRedhat.comRH:CVE-2024-26649
HistoryMar 27, 2024 - 2:01 p.m.

CVE-2024-26649

2024-03-2714:01:49
redhat.com
access.redhat.com
2
linux kernel
amdgpu driver
vulnerability

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

A vulnerability was found in the drm/amdgpu driver of Linux Kernel, causing null pointer dereference when attempting to load RLC (Run-Length Coding) firmware. This issue arises if the firmware has an incorrect header size, causing premature release of the firmware pointer in amdgpu_ucode_request(), subsequently attempts to use the nullified pointer result in errors.

Mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%