CVE-2024-38549

Source
https://cve.org/CVERecord?id=CVE-2024-38549
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38549.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-38549
Downstream
Related
Published
2024-06-19T13:35:22.042Z
Modified
2026-05-13T03:52:19.958166259Z
Summary
drm/mediatek: Add 0 size check to mtk_drm_gem_obj
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: Add 0 size check to mtkdrmgem_obj

Add a check to mtkdrmgem_init if we attempt to allocate a GEM object of 0 bytes. Currently, no such check exists and the kernel will panic if a userspace application attempts to allocate a 0x0 GBM buffer.

Tested by attempting to allocate a 0x0 GBM buffer on an MT8188 and verifying that we now return EINVAL.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38549.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
119f5173628aa7a0c3cf9db83460d40709e8241d
Fixed
79078880795478d551a05acc41f957700030d364
Fixed
be34a1b351ea7faeb15dde8c44fe89de3980ae67
Fixed
d17b75ee9c2e44d3a3682c4ea5ab713ea6073350
Fixed
0e3b6f9123726858cac299e1654e3d20424cabe4
Fixed
13562c2d48c9ee330de1077d00146742be368f05
Fixed
af26ea99019caee1500bf7e60c861136c0bf8594
Fixed
9489951e3ae505534c4013db4e76b1b5a3151ac7
Fixed
fb4aabdb1b48c25d9e1ee28f89440fd2ce556405
Fixed
1e4350095e8ab2577ee05f8c3b044e661b5af9a0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38549.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
4.19.316
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.278
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.219
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.161
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.93
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.33
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.12
Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.9.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38549.json"