Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A memory corruption vulnerability has been addressed in the Linux kernel's Direct Rendering Manager (DRM) for the Qualcomm MSM graphics driver. This issue arises from the handling of DisplayPort (DP) bridges, where the absence of a proper sanity check on the bridge counter can lead to data corruption. The vulnerability is present in versions of the Linux kernel that include the problematic bridge mechanism for DisplayPort management.
Exploitation of this vulnerability could lead to memory corruption, potentially allowing for arbitrary code execution or causing a system crash.
The vulnerability can be reproduced by configuring a DisplayPort device with more than eight bridges. The missing sanity check on the bridge counter will cause data to be written beyond the bounds of the fixed-size bridge array, leading to memory corruption.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for upgrading the Linux kernel can be found in the official Linux documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.