#VU100151 Resource management error in Linux kernel - CVE-2024-50201


Vulnerability identifier: #VU100151

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50201

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the radeon_encoder_clones() function in drivers/gpu/drm/radeon/radeon_encoders.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/df75c78bfeff99f9b4815c3e79e2b1b1e34fe264
https://git.kernel.org/stable/c/fda5dc80121b12871dc343ab37e0c3f0d138825d
https://git.kernel.org/stable/c/c3cd27d85f0778f4ec07384d7516b33153759b8e
https://git.kernel.org/stable/c/1a235af0216411a32ab4db54f7bd19020b46c86d
https://git.kernel.org/stable/c/68801730ebb9393460b30cd3885e407f15da27a9
https://git.kernel.org/stable/c/28127dba64d8ae1a0b737b973d6d029908599611


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability