
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-50004 affects the Linux kernel's AMD display driver, specifically related to the DML2 policy in DCN35. The vulnerability was discovered and disclosed on October 21, 2024, affecting Linux kernel versions up to 6.10.14 and from 6.11 up to 6.11.3. The issue involves a mismatch in DCN35 DML2 that causes bandwidth validation failures (Kernel Git).
The vulnerability stems from a mismatch in the DCN35 DML2 implementation where bandwidth validation fails to acquire the expected DPP pipe, resulting in a grey screen and system hang. The issue specifically relates to an incorrect EnhancedPrefetchScheduleAccelerationFinal value override that doesn't match hardware specifications. The vulnerability has been assigned a CVSS v3.1 score of 5.5 (Medium) (NVD).
When exploited, this vulnerability can cause system hangs and display issues, specifically resulting in grey screens. The impact is primarily on system availability and stability, affecting systems using AMD display drivers with DCN35 hardware (NVD).
The issue has been resolved by removing the EnhancedPrefetchScheduleAccelerationFinal value override to match hardware specifications. The fix has been implemented through patches in the Linux kernel. Users should update to kernel versions that include these patches (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."