CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-50003: drm/amd/display: Fix system hang while resume with TBT monitor

5.5 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Fix system hang while resume with TBT monitor

[Why]
Connected with a Thunderbolt monitor and do the suspend and the system
may hang while resume.

The TBT monitor HPD will be triggered during the resume procedure
and call the drm_client_modeset_probe() while
struct drm_connector connector->dev->master is NULL.

It will mess up the pipe topology after resume.

[How]
Skip the TBT monitor HPD during the resume procedure because we
currently will probe the connectors after resume by default.

(cherry picked from commit 453f86a26945207a16b8f66aaed5962dc2b95b85)

Classification

CVE ID: CVE-2024-50003

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.5

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.63% (scored less or equal to compared to others)

EPSS Date: 2025-06-02 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-50003
https://git.kernel.org/stable/c/eb9329cd882aa274e92bdb1003bc088433fdee86
https://git.kernel.org/stable/c/722d2d8fc423108597b97efbf165187d16d9aa1e
https://git.kernel.org/stable/c/68d603f467a75618eeae5bfe8af32cda47097010
https://git.kernel.org/stable/c/73e441be033d3ed0bdff09b575da3e7d4606ffc9
https://git.kernel.org/stable/c/c2356296f546326f9f06c109e201d42201e1e783
https://git.kernel.org/stable/c/52d4e3fb3d340447dcdac0e14ff21a764f326907

Timeline