CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
[Why]
Coverity reports OVERRUN warning. Should abort amdgpu_dm
initialize.
[How]
Return failure to amdgpu_dm_init.
Security readout for executives and security teams
Plain-English summary
A Linux AMD graphics display-driver flaw can overrun an internal limit when more than six display streams are encountered during initialization. Successful triggering could compromise confidentiality, integrity, and availability, but the supplied assessment requires local access and high attack complexity. Systems without the affected AMD display path are unlikely to be exposed.
Executive priority
Treat as a high-priority kernel update for AMD graphics fleets, but below remotely exploitable or confirmed-active threats. Accelerate remediation on workstations, visualization hosts, and other systems using complex display configurations. Standard patch cadence may be reasonable where the AMD display driver is absent or the vulnerable path is demonstrably unreachable.
Technical view
The amdgpu display manager failed to stop initialization when the stream count exceeded six, producing a Coverity-reported overrun condition. The upstream correction makes amdgpu_dm_init return failure in that case. CVSS 3.1 is 7.4: local, high-complexity, no privileges or user interaction, with potentially high impact across confidentiality, integrity, and availability.
Likely exposure
Prioritize Linux endpoints using AMD GPUs and the amdgpu display stack, particularly systems with complex multi-display or virtual-display configurations. The supplied affected-version data includes kernels from 4.15 through 6.11 but is ambiguous rather than a reliable range definition. Confirm exposure using distribution advisories and the presence of the applicable stable fix.
Exploitation context
No active exploitation is established: the bundle marks this CVE absent from KEV and supplies no public exploitation evidence. The CVSS vector describes a local, high-complexity path requiring neither privileges nor user interaction. Practical reachability depends on the affected AMD display initialization path encountering more than six streams.
Researcher notes
The source description identifies an initialization overrun boundary and the defensive change, but does not document the corrupted object, triggering control, crash behavior, or demonstrated exploitability. Exact affected ranges are unclear because the bundle mixes versions, duplicate commit identifiers, and default statuses. Validate using distribution-specific backport records rather than version numbers alone.
Mitigation direction
Install a vendor-supported kernel package containing the applicable stable fix.
Use Debian or other distribution advisories to identify corrected package versions.
Prioritize AMD GPU systems with complex display configurations.
If immediate updating is impossible, reduce unnecessary display-stream complexity after operational review.
Validation and detection
Inventory kernel versions and identify systems loading the AMD display driver.
Compare installed packages with vendor advisory fixed versions.
Confirm the applicable stable patch is present in custom kernels.
After updating, verify normal driver initialization and display operation.
Review system logs for AMD display initialization or overrun-related failures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-46817 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.