U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-38390

Change History

New CVE Received by NIST 6/21/2024 7:15:10 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails

Calling a6xx_destroy() before adreno_gpu_init() leads to a null pointer
dereference on:

msm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL);

as gpu->pdev is only assigned in:

a6xx_gpu_init()
|_ adreno_gpu_init
    |_ msm_gpu_init()

Instead of relying on handwavy null checks down the cleanup chain,
explicitly de-allocate the LLC data and free a6xx_gpu instead.

Patchwork: https://patchwork.freedesktop.org/patch/588919/
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/247849eeb3fd88f8990ed73e33af70d5c10f9aec [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/46d4efcccc688cbacdd70a238bedca510acaa8e4 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/617e3d1680504a3f9d88e1582892c68be155498f [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/a1955a6df91355fef72a3a254700acd3cc1fec0d [No types assigned]