CVE-2024-52557: drm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get()
In the Linux kernel, the following vulnerability has been resolved:
drm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get()
This patch fixes a potential integer overflow in the zynqmp_dp_rate_get()
The issue comes up when the expression
drm_dp_bw_code_to_link_rate(dp->test.bw_code) * 10000 is evaluated using 32-bit
Now the constant is a compatible 64-bit type.
Resolves coverity issues: CID 1636340 and CID 1635811
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel availability issue in the ZynqMP DisplayPort driver. A local, low-privileged user could trigger an integer overflow path that may crash or disrupt the affected system. It is not described as exposing data or enabling remote compromise.
Executive priority
Handle during normal kernel maintenance unless the organization operates shared or multi-user ZynqMP systems. Escalate if affected devices support critical services where a local crash would disrupt operations.
Technical view
CVE-2024-52557 is a CWE-190 integer overflow in zynqmp_dp_rate_get(). The vulnerable calculation multiplies a DisplayPort bandwidth-derived link rate by 10000 using 32-bit evaluation; the fix makes the constant 64-bit compatible. CVSS 3.1 is 5.5, local attack vector, low complexity, low privileges, availability impact high.
Likely exposure
Exposure is most likely on Linux systems using the ZynqMP DisplayPort DRM driver with affected kernel builds. General Linux servers without this hardware or driver path are less likely to be exposed. The provided source data names Linux kernel versions and stable commits, but not specific distributions or downstream vendor backports.
Exploitation context
The CVE record does not report known active exploitation, and KEV status is false in the supplied bundle. The CVSS vector indicates local access and low privileges are required. Treat it mainly as a local denial-of-service risk until vendor or distribution advisories provide more detail.
Researcher notes
Evidence is limited to the CVE record and upstream stable commits. The issue is a narrow arithmetic overflow fix in a hardware-specific DRM driver. No public exploit activity, distribution impact matrix, or detailed trigger conditions are provided in the supplied sources.
Mitigation direction
Apply a kernel update containing the referenced stable fixes or a vendor backport.
Check distribution and device vendor advisories for corrected kernel packages.
Prioritize systems using ZynqMP DisplayPort hardware with local user access.
Reduce unnecessary local interactive access on affected systems until patched.
Track kernel provenance where vendor kernels differ from upstream stable releases.
Validation and detection
Inventory Linux kernel versions and builds on ZynqMP-based systems.
Confirm whether the zynqmp_dp DisplayPort driver is present or enabled.
Verify the kernel includes one of the referenced upstream stable fixes or an equivalent backport.
Review distribution changelogs for CVE-2024-52557 coverage.
Document non-exposure where the affected driver or hardware is absent.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-190: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-190 · source CWE mapping
Integer Overflow or Wraparound
Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.