CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-44977: drm/amdgpu: Validate TA binary size

7.8 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Validate TA binary size

Add TA binary size validation to avoid OOB write.

(cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)

Classification

CVE ID: CVE-2024-44977

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 12.34% (scored less or equal to compared to others)

EPSS Date: 2025-06-02 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-44977
https://git.kernel.org/stable/c/5ab8793b9a6cc059f503cbe6fe596f80765e0f19
https://git.kernel.org/stable/c/50553ea7cbd3344fbf40afb065f6a2d38171c1ad
https://git.kernel.org/stable/c/e562415248f402203e7fb6d8c38c1b32fa99220f
https://git.kernel.org/stable/c/c99769bceab4ecb6a067b9af11f9db281eea3e2a

Timeline