CVE-2024-26914

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix incorrect mpc_combine array size [why] MAX_SURFACES is per stream, while MAX_PLANES is per asic. The mpc_combine is an array that records all the planes per asic. Therefore MAX_PLANES should be used as the array size. Using MAX_SURFACES causes array overflow when there are more than 3 planes. [how] Use the MAX_PLANES for the mpc_combine array size.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*

History

16 Sep 2025, 16:40

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-129
References () https://git.kernel.org/stable/c/0bd8ef618a42d7e6ea3f701065264e15678025e3 - () https://git.kernel.org/stable/c/0bd8ef618a42d7e6ea3f701065264e15678025e3 - Patch
References () https://git.kernel.org/stable/c/39079fe8e660851abbafa90cd55cbf029210661f - () https://git.kernel.org/stable/c/39079fe8e660851abbafa90cd55cbf029210661f - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Linux
Linux linux Kernel

21 Nov 2024, 09:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0bd8ef618a42d7e6ea3f701065264e15678025e3 - () https://git.kernel.org/stable/c/0bd8ef618a42d7e6ea3f701065264e15678025e3 -
References () https://git.kernel.org/stable/c/39079fe8e660851abbafa90cd55cbf029210661f - () https://git.kernel.org/stable/c/39079fe8e660851abbafa90cd55cbf029210661f -

17 Apr 2024, 16:51

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-17 16:15

Updated : 2025-09-16 16:40


NVD link : CVE-2024-26914

Mitre link : CVE-2024-26914

CVE.ORG link : CVE-2024-26914


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-129

Improper Validation of Array Index