CVE-2024-38548: drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference

Description

In the Linux kernel, the following vulnerability has been resolved:

drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference

In cdns_mhdp_atomic_enable(), the return value of drm_mode_duplicate() is
assigned to mhdp_state->current_mode, and there is a dereference of it in
drm_mode_set_name(), which will lead to a NULL pointer dereference on
failure of drm_mode_duplicate().

Fix this bug add a check of mhdp_state->current_mode.

Classification

CVE ID: CVE-2024-38548

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 12.41% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/85d1a27402f81f2e04b0e67d20f749c2a14edbb3
https://git.kernel.org/stable/c/89788cd9824c28ffcdea40232c458233353d1896
https://git.kernel.org/stable/c/ca53b7efd4ba6ae92fd2b3085cb099c745e96965
https://git.kernel.org/stable/c/dcf53e6103b26e7458be71491d0641f49fbd5840
https://git.kernel.org/stable/c/32fb2ef124c3301656ac6c789a2ef35ef69a66da
https://git.kernel.org/stable/c/47889711da20be9b43e1e136e5cb68df37cbcc79
https://git.kernel.org/stable/c/935a92a1c400285545198ca2800a4c6c519c650a

Timeline