CVE-2024-40926: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: don't attempt to schedule hpd_work on headless cards If the card doesn't have display hardware, hpd_work and hpd_lock are left uninitialized which causes BUG when attempting to schedule hpd_work on runtime PM resume. Fix it by adding headless flag to DRM and skip any hpd if it's set.

Affected products

  • Linux Linux Kernel: from 6.7, before 6.9.6 (fixed in 6.9.6); version 6.10 only

Published 2024-07-12. Last modified 2026-06-17.