CVE-2024-38548

Source
https://cve.org/CVERecord?id=CVE-2024-38548
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38548.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-38548
Downstream
Related
Published
2024-06-19T13:35:21.349Z
Modified
2026-05-28T03:53:02.228402420Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference
Details

In the Linux kernel, the following vulnerability has been resolved:

drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference

In cdnsmhdpatomicenable(), the return value of drmmodeduplicate() is assigned to mhdpstate->currentmode, and there is a dereference of it in drmmodesetname(), which will lead to a NULL pointer dereference on failure of drmmodeduplicate().

Fix this bug add a check of mhdpstate->currentmode.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38548.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fb43aa0acdfd600c75b8c877bdf9f6e9893ffc9b
Fixed
85d1a27402f81f2e04b0e67d20f749c2a14edbb3
Fixed
89788cd9824c28ffcdea40232c458233353d1896
Fixed
ca53b7efd4ba6ae92fd2b3085cb099c745e96965
Fixed
dcf53e6103b26e7458be71491d0641f49fbd5840
Fixed
32fb2ef124c3301656ac6c789a2ef35ef69a66da
Fixed
47889711da20be9b43e1e136e5cb68df37cbcc79
Fixed
935a92a1c400285545198ca2800a4c6c519c650a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38548.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.219
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.161
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.93
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.33
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.12
Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.9.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38548.json"