LiveActive security incident?Get immediate response
CVE Record

CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 [Why] Coverity reports OVERRUN warning. Should abort amdgpu_dm initialize. [How] Return failure to amdgpu_dm_init.

HighCVSS 7.4Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux AMD graphics display-driver flaw can overrun an internal limit when more than six display streams are encountered during initialization. Successful triggering could compromise confidentiality, integrity, and availability, but the supplied assessment requires local access and high attack complexity. Systems without the affected AMD display path are unlikely to be exposed.

Executive priority

Treat as a high-priority kernel update for AMD graphics fleets, but below remotely exploitable or confirmed-active threats. Accelerate remediation on workstations, visualization hosts, and other systems using complex display configurations. Standard patch cadence may be reasonable where the AMD display driver is absent or the vulnerable path is demonstrably unreachable.

Technical view

The amdgpu display manager failed to stop initialization when the stream count exceeded six, producing a Coverity-reported overrun condition. The upstream correction makes amdgpu_dm_init return failure in that case. CVSS 3.1 is 7.4: local, high-complexity, no privileges or user interaction, with potentially high impact across confidentiality, integrity, and availability.

Likely exposure

Prioritize Linux endpoints using AMD GPUs and the amdgpu display stack, particularly systems with complex multi-display or virtual-display configurations. The supplied affected-version data includes kernels from 4.15 through 6.11 but is ambiguous rather than a reliable range definition. Confirm exposure using distribution advisories and the presence of the applicable stable fix.

Exploitation context

No active exploitation is established: the bundle marks this CVE absent from KEV and supplies no public exploitation evidence. The CVSS vector describes a local, high-complexity path requiring neither privileges nor user interaction. Practical reachability depends on the affected AMD display initialization path encountering more than six streams.

Researcher notes

The source description identifies an initialization overrun boundary and the defensive change, but does not document the corrupted object, triggering control, crash behavior, or demonstrated exploitability. Exact affected ranges are unclear because the bundle mixes versions, duplicate commit identifiers, and default statuses. Validate using distribution-specific backport records rather than version numbers alone.

Mitigation direction

  • Install a vendor-supported kernel package containing the applicable stable fix.
  • Use Debian or other distribution advisories to identify corrected package versions.
  • Prioritize AMD GPU systems with complex display configurations.
  • If immediate updating is impossible, reduce unnecessary display-stream complexity after operational review.

Validation and detection

  • Inventory kernel versions and identify systems loading the AMD display driver.
  • Compare installed packages with vendor advisory fixed versions.
  • Confirm the applicable stable patch is present in custom kernels.
  • After updating, verify normal driver initialization and display operation.
  • Review system logs for AMD display initialization or overrun-related failures.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-46817 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.4CVSS 3.1HighCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H1.45.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.4High
CVSS 3.1 vector shape for CVE-2024-46817Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c, 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7cunaffected
LinuxLinux4.15, 0, 5.4.284, 5.10.226, 5.15.167, 6.1.109, 6.6.50, 6.10.9, 6.11affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.