In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: Fix integer overflow in radeoncsparser_init
The type of size is unsigned, if size is 0x40000000, there will be an integer overflow, size will be zero after size *= sizeof(uint32_t), will cause uninitialized memory to be referenced later