Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.10, < 6.10.0-rc1
A vulnerability in the Linux kernel's handling of media graphics technology (GT) can lead to a NULL pointer dereference, causing a kernel page fault. This issue occurs in the HDCP (High-bandwidth Digital Content Protection) status check function when media GT is disabled, leaving the media GT pointer NULL. The function then attempts to access an invalid memory address, resulting in a crash. The vulnerability affects Linux kernel versions 6.10 and later.
Exploitation of this vulnerability causes a kernel page fault, leading to a system crash.
The vulnerability can be reproduced by disabling media GT via configfs, which leaves the media GT pointer NULL. When the HDCP status check function is called in this state, it attempts to access the NULL pointer, causing a page fault and crashing the kernel.
Users can upgrade to the latest version of the Linux kernel to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.