Bug 2373425 (CVE-2022-50079) - CVE-2022-50079 kernel: drm/amd/display: Check correct bounds for stream encoder instances for DCN303
Summary: CVE-2022-50079 kernel: drm/amd/display: Check correct bounds for stream encod...
Keywords:
Status: NEW
Alias: CVE-2022-50079
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-18 12:02 UTC by OSIDB Bzimport
Modified: 2025-06-20 09:28 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-18 12:02:17 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Check correct bounds for stream encoder instances for DCN303

[Why & How]
eng_id for DCN303 cannot be more than 1, since we have only two
instances of stream encoders.

Check the correct boundary condition for engine ID for DCN303 prevent
the potential out of bounds access.

Comment 1 Avinash Hanwate 2025-06-20 09:19:03 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025061856-CVE-2022-50079-b3a5@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.