CVE-2024-46724·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds read error
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.9
- Published
- 2024-09-18
Affected versions
From: 6.7
Until: 6.10.9
Fixed in: 6.10.9
How to fix this CVE
Update your Linux kernel to version 6.10.9 or later to address an out-of-bounds memory read vulnerability in the AMD GPU driver's data fabric module. This flaw could allow local attackers with standard user privileges to read sensitive kernel memory or trigger a denial-of-service condition. Prioritize this patch if you operate AMD GPU-equipped systems in multi-tenant or untrusted environments.
sudo dnf update kernel kernel-devel kernel-headersDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to display your current kernel version and compare against the affected range 6.7-6.10.8
- Check if AMD GPU support is compiled into your kernel with 'grep -i amdgpu /boot/config-$(uname -r)' — look for CONFIG_DRM_AMDGPU=y or =m
- Search kernel logs for memory access violations related to df_v1_7_channel_number by running 'dmesg | grep -i "amdgpu\|df_v1_7\|out.of.bounds"'
- Verify the patch is applied by checking if the kernel version is 6.10.9 or newer with 'uname -r' and confirming no amdgpu-related warnings appear in 'journalctl -xe'
FAQ
What is CVE-2024-46724?
This vulnerability is an out-of-bounds array read in the AMD GPU driver's data fabric module that occurs when the kernel fails to validate channel numbers before accessing memory. A local attacker with user-level permissions could exploit this to leak sensitive kernel memory or crash the system.
Is CVE-2024-46724 being actively exploited?
No, CVE-2024-46724 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available. However, it remains a high-severity local privilege escalation vector that should be remediated promptly.
What versions of Kernel are affected by CVE-2024-46724?
Linux kernel versions 6.7 through 6.10.8 are vulnerable. The fix is available in kernel 6.10.9 and all subsequent releases.
How do I check if my server is vulnerable to CVE-2024-46724?
Run 'uname -r' to display your kernel version. If it reports a version between 6.7 and 6.10.8, and your kernel has AMD GPU (amdgpu) support enabled, your system is vulnerable.
Does Defensia detect CVE-2024-46724?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-46724 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/32915dc909ff502823babfe07d5416c5b6e8a8b1
- https://git.kernel.org/stable/c/45f7b02afc464c208e8f56bcbc672ef5c364c815
- https://git.kernel.org/stable/c/725b728cc0c8c5fafdfb51cb0937870d33a40fa4
- https://git.kernel.org/stable/c/d768394fa99467bcf2703bde74ddc96eeb0b71fa
- https://git.kernel.org/stable/c/db7a86676fd624768a5d907faf34ad7bb4ff25f4
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-46724. Free for 1 server.
Get started free