Bugzilla – Bug 1222055
VUL-0: CVE-2024-26649: kernel: drm/amdgpu: NULL pointer dereference when loading rlc firmware
Last modified: 2024-06-25 18:23:03 UTC
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the null pointer when load rlc firmware If the RLC firmware is invalid because of wrong header size, the pointer to the rlc firmware is released in function amdgpu_ucode_request. There will be a null pointer error in subsequent use. So skip validation to fix it. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-26649 https://www.cve.org/CVERecord?id=CVE-2024-26649 https://git.kernel.org/stable/c/8b5bacce2d13dbe648f0bfd3f738ecce8db4978c https://git.kernel.org/stable/c/bc03c02cc1991a066b23e69bbcc0f66e8f1f7453 https://git.kernel.org/stable/c/d3887448486caeef9687fb5dfebd4ff91e0f25aa https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-26649.mbox
Already fixed in SLE15-SP6-GA, older branches are not affected.
All done, closing.