In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix potential out-of-bounds access in 'amdgpudiscoveryregbaseinit()'
The issue arises when the array 'adev->vcn.vcnconfig' is accessed before checking if the index 'adev->vcn.numvcn_inst' is within the bounds of the array.
The fix involves moving the bounds check before the array access. This ensures that 'adev->vcn.numvcninst' is within the bounds of the array before it is used as an index.
Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpudiscovery.c:1289 amdgpudiscoveryregbaseinit() error: testing array offset 'adev->vcn.numvcn_inst' after use.
[
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"325934718580591288597826448686130467692",
"284786933653546711023637314193963399087",
"189201165371388698135764915485907846048",
"143596053723739716790578732854107212385",
"160131513625955665558058711123419927239",
"200097109772373505885742461586637820",
"295932610915831657954429951536272647052",
"312587483094128070105842236988162525571",
"299508806778327091189582542134343259952",
"314120920920270877669497194989433186775",
"276041800460652937651216354377040764883",
"164241774896110428046406825861242471705"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cdb637d339572398821204a1142d8d615668f1e9",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c"
},
"id": "CVE-2024-27042-07c545e0",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"325934718580591288597826448686130467692",
"284786933653546711023637314193963399087",
"189201165371388698135764915485907846048",
"143596053723739716790578732854107212385",
"160131513625955665558058711123419927239",
"200097109772373505885742461586637820",
"295932610915831657954429951536272647052",
"312587483094128070105842236988162525571",
"299508806778327091189582542134343259952",
"314120920920270877669497194989433186775",
"276041800460652937651216354377040764883",
"164241774896110428046406825861242471705"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b33d4af102b9c1f7a83d3f0ad3cab7d2bab8f058",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c"
},
"id": "CVE-2024-27042-226ab00c",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "10820051316388430058542518892984072281",
"length": 3603.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f3e68c6a3fff53c2240762a47a0045d89371775",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c",
"function": "amdgpu_discovery_reg_base_init"
},
"id": "CVE-2024-27042-2f676df8",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"325934718580591288597826448686130467692",
"284786933653546711023637314193963399087",
"189201165371388698135764915485907846048",
"143596053723739716790578732854107212385",
"160131513625955665558058711123419927239",
"200097109772373505885742461586637820",
"295932610915831657954429951536272647052",
"312587483094128070105842236988162525571",
"299508806778327091189582542134343259952",
"314120920920270877669497194989433186775",
"276041800460652937651216354377040764883",
"164241774896110428046406825861242471705"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f3e68c6a3fff53c2240762a47a0045d89371775",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c"
},
"id": "CVE-2024-27042-73cc08af",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "27690968175424770862108225814831430446",
"length": 3733.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cdb637d339572398821204a1142d8d615668f1e9",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c",
"function": "amdgpu_discovery_reg_base_init"
},
"id": "CVE-2024-27042-8ca7ba28",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "27690968175424770862108225814831430446",
"length": 3733.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8db10cee51e3e11a6658742465edc21986cf1e8d",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c",
"function": "amdgpu_discovery_reg_base_init"
},
"id": "CVE-2024-27042-b93f9aa2",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"325934718580591288597826448686130467692",
"284786933653546711023637314193963399087",
"189201165371388698135764915485907846048",
"143596053723739716790578732854107212385",
"160131513625955665558058711123419927239",
"200097109772373505885742461586637820",
"295932610915831657954429951536272647052",
"312587483094128070105842236988162525571",
"299508806778327091189582542134343259952",
"314120920920270877669497194989433186775",
"276041800460652937651216354377040764883",
"164241774896110428046406825861242471705"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8db10cee51e3e11a6658742465edc21986cf1e8d",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c"
},
"id": "CVE-2024-27042-c21a4dcd",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "27690968175424770862108225814831430446",
"length": 3733.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b33d4af102b9c1f7a83d3f0ad3cab7d2bab8f058",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c",
"function": "amdgpu_discovery_reg_base_init"
},
"id": "CVE-2024-27042-e574d5c2",
"deprecated": false,
"signature_version": "v1"
}
]