CVE-2024-49913: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream This commit addresses a null pointer dereference issue in the `commit_planes_for_stream` function at line 4140. The issue could occur when `top_pipe_to_program` is null. The fix adds a check to ensure `top_pipe_to_program` is not null before accessing its stream_res. This prevents a null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)

Affected products

  • Linux Linux Kernel: before 5.10.227 (fixed in 5.10.227); from 5.11, before 5.15.168 (fixed in 5.15.168); from 5.16, before 6.1.113 (fixed in 6.1.113); from 6.2, before 6.6.55 (fixed in 6.6.55); from 6.7, before 6.10.14 (fixed in 6.10.14); from 6.11, before 6.11.3 (fixed in 6.11.3)

Published 2024-10-21. Last modified 2026-06-17.