Sign in
Sign up
Explore
Enterprise
Education
Search
Help
Terms of use
About Us
Explore
Enterprise
Education
Gitee Premium
Gitee AI
AI teammates
Sign in
Sign up
Fetch the repository succeeded.
description of repo status
Open Source
>
Other
>
Operation System
&&
Watch
Unwatch
Watching
Releases Only
Ignoring
128
Star
73
Fork
331
src-openEuler
/
kernel
Closed
Code
Issues
1197
Pull Requests
35
Wiki
Insights
Pipelines
Service
JavaDoc
PHPDoc
Quality Analysis
Jenkins for Gitee
Tencent CloudBase
Tencent Cloud Serverless
悬镜安全
Aliyun SAE
Codeblitz
SBOM
DevLens
Don’t show this again
Update failed. Please try again later!
Remove this flag
Content Risk Flag
This task is identified by
as the content contains sensitive information such as code security bugs, privacy leaks, etc., so it is only accessible to contributors of this repository.
CVE-2024-40916
Done
#IACQYH
CVE和安全问题
openeuler-ci-bot
owner
Opened this issue
2024-07-13 16:02
一、漏洞信息 漏洞编号:[CVE-2024-40916](https://nvd.nist.gov/vuln/detail/CVE-2024-40916) 漏洞归属组件:[kernel](https://gitee.com/src-openeuler/kernel) 漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.0,6.1.14,6.1.19,6.1.5,6.1.6,6.1.8,6.4.0,6.6.0 CVSS V2.0分值: BaseScore:0.0 Low Vector:CVSS:2.0/ 漏洞简述: In the Linux kernel, the following vulnerability has been resolved:drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID foundWhen reading EDID fails and driver reports no modes available, the DRMcore adds an artificial 1024x786 mode to the connector. Unfortunatelysome variants of the Exynos HDMI (like the one in Exynos4 SoCs) are notable to drive such mode, so report a safe 640x480 mode instead of nothingin case of the EDID reading failure.This fixes the following issue observed on Trats2 board since commit13d5b040363c ( drm/exynos: do not return negative values from .get_modes() ):[drm] Exynos DRM: using 11c00000.fimd device for DMA mapping operationsexynos-drm exynos-drm: bound 11c00000.fimd (ops fimd_component_ops)exynos-drm exynos-drm: bound 12c10000.mixer (ops mixer_component_ops)exynos-dsi 11c80000.dsi: [drm:samsung_dsim_host_attach] Attached s6e8aa0 device (lanes:4 bpp:24 mode-flags:0x10b)exynos-drm exynos-drm: bound 11c80000.dsi (ops exynos_dsi_component_ops)exynos-drm exynos-drm: bound 12d00000.hdmi (ops hdmi_component_ops)[drm] Initialized exynos 1.1.0 20180330 for exynos-drm on minor 1exynos-hdmi 12d00000.hdmi: [drm:hdmiphy_enable.part.0] *ERROR* PLL could not reach steady statepanel-samsung-s6e8aa0 11c80000.dsi.0: ID: 0xa2, 0x20, 0x8cexynos-mixer 12c10000.mixer: timeout waiting for VSYNC------------[ cut here ]------------WARNING: CPU: 1 PID: 11 at drivers/gpu/drm/drm_atomic_helper.c:1682 drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8[CRTC:70:crtc-1] vblank wait timed outModules linked in:CPU: 1 PID: 11 Comm: kworker/u16:0 Not tainted 6.9.0-rc5-next-20240424 #14913Hardware name: Samsung Exynos (Flattened Device Tree)Workqueue: events_unbound deferred_probe_work_funcCall trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x68/0x88 dump_stack_lvl from __warn+0x7c/0x1c4 __warn from warn_slowpath_fmt+0x11c/0x1a8 warn_slowpath_fmt from drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8 drm_atomic_helper_wait_for_vblanks.part.0 from drm_atomic_helper_commit_tail_rpm+0x7c/0x8c drm_atomic_helper_commit_tail_rpm from commit_tail+0x9c/0x184 commit_tail from drm_atomic_helper_commit+0x168/0x190 drm_atomic_helper_commit from drm_atomic_commit+0xb4/0xe0 drm_atomic_commit from drm_client_modeset_commit_atomic+0x23c/0x27c drm_client_modeset_commit_atomic from drm_client_modeset_commit_locked+0x60/0x1cc drm_client_modeset_commit_locked from drm_client_modeset_commit+0x24/0x40 drm_client_modeset_commit from __drm_fb_helper_restore_fbdev_mode_unlocked+0x9c/0xc4 __drm_fb_helper_restore_fbdev_mode_unlocked from drm_fb_helper_set_par+0x2c/0x3c drm_fb_helper_set_par from fbcon_init+0x3d8/0x550 fbcon_init from visual_init+0xc0/0x108 visual_init from do_bind_con_driver+0x1b8/0x3a4 do_bind_con_driver from do_take_over_console+0x140/0x1ec do_take_over_console from do_fbcon_takeover+0x70/0xd0 do_fbcon_takeover from fbcon_fb_registered+0x19c/0x1ac fbcon_fb_registered from register_framebuffer+0x190/0x21c register_framebuffer from __drm_fb_helper_initial_config_and_unlock+0x350/0x574 __drm_fb_helper_initial_config_and_unlock from exynos_drm_fbdev_client_hotplug+0x6c/0xb0 exynos_drm_fbdev_client_hotplug from drm_client_register+0x58/0x94 drm_client_register from exynos_drm_bind+0x160/0x190 exynos_drm_bind from try_to_bring_up_aggregate_device+0x200/0x2d8 try_to_bring_up_aggregate_device from __component_add+0xb0/0x170 __component_add from mixer_probe+0x74/0xcc mixer_probe from platform_probe+0x5c/0xb8 platform_probe from really_probe+0xe0/0x3d8 really_probe from __driver_probe_device+0x9c/0x1e4 __driver_probe_device from driver_probe_device+0x30/0xc0 driver_probe_device from __device_attach_driver+0xa8/0x120 __device_attach_driver from bus_for_each_drv+0x80/0xcc bus_for_each_drv from __device_attach+0xac/0x1fc __device_attach from bus_probe_device+0x8c/0x90 bus_probe_device from deferred_probe_work_func+0---truncated--- 漏洞公开时间:2024-07-12 21:15:14 漏洞创建时间:2024-07-13 16:02:05 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2024-40916 <details> <summary>更多参考(点击展开)</summary> | 参考来源 | 参考链接 | 来源链接 | | ------- | -------- | -------- | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | | | suse_bugzilla | http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-40916 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://www.cve.org/CVERecord?id=CVE-2024-40916 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-40916.mbox | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | ubuntu | https://www.cve.org/CVERecord?id=CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/linus/799d4b392417ed6889030a5b2335ccb6dcf030ab (6.10-rc4) | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://nvd.nist.gov/vuln/detail/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://launchpad.net/bugs/cve/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://security-tracker.debian.org/tracker/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | debian | | https://security-tracker.debian.org/tracker/CVE-2024-40916 | </details> 漏洞分析指导链接: https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md 漏洞数据来源: openBrain开源漏洞感知系统 漏洞补丁信息: <details> <summary>详情(点击展开)</summary> | 影响的包 | 修复版本 | 修复补丁 | 问题引入补丁 | 来源 | | ------- | -------- | ------- | -------- | --------- | | linux | | https://git.kernel.org/linus/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://git.kernel.org/linus/1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 | ubuntu | </details> 二、漏洞分析结构反馈 影响性分析说明: In the Linux kernel, the following vulnerability has been resolved:drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID foundWhen reading EDID fails and driver reports no modes available, the DRMcore adds an artificial 1024x786 mode to the connector. Unfortunatelysome variants of the Exynos HDMI (like the one in Exynos4 SoCs) are notable to drive such mode, so report a safe 640x480 mode instead of nothingin case of the EDID reading failure.This fixes the following issue observed on Trats2 board since commit13d5b040363c ("drm/exynos: do not return negative values from .get_modes()"):[drm] Exynos DRM: using 11c00000.fimd device for DMA mapping operationsexynos-drm exynos-drm: bound 11c00000.fimd (ops fimd_component_ops)exynos-drm exynos-drm: bound 12c10000.mixer (ops mixer_component_ops)exynos-dsi 11c80000.dsi: [drm:samsung_dsim_host_attach] Attached s6e8aa0 device (lanes:4 bpp:24 mode-flags:0x10b)exynos-drm exynos-drm: bound 11c80000.dsi (ops exynos_dsi_component_ops)exynos-drm exynos-drm: bound 12d00000.hdmi (ops hdmi_component_ops)[drm] Initialized exynos 1.1.0 20180330 for exynos-drm on minor 1exynos-hdmi 12d00000.hdmi: [drm:hdmiphy_enable.part.0] *ERROR* PLL could not reach steady statepanel-samsung-s6e8aa0 11c80000.dsi.0: ID: 0xa2, 0x20, 0x8cexynos-mixer 12c10000.mixer: timeout waiting for VSYNC------------[ cut here ]------------WARNING: CPU: 1 PID: 11 at drivers/gpu/drm/drm_atomic_helper.c:1682 drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8[CRTC:70:crtc-1] vblank wait timed outModules linked in:CPU: 1 PID: 11 Comm: kworker/u16:0 Not tainted 6.9.0-rc5-next-20240424 #14913Hardware name: Samsung Exynos (Flattened Device Tree)Workqueue: events_unbound deferred_probe_work_funcCall trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x68/0x88 dump_stack_lvl from __warn+0x7c/0x1c4 __warn from warn_slowpath_fmt+0x11c/0x1a8 warn_slowpath_fmt from drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8 drm_atomic_helper_wait_for_vblanks.part.0 from drm_atomic_helper_commit_tail_rpm+0x7c/0x8c drm_atomic_helper_commit_tail_rpm from commit_tail+0x9c/0x184 commit_tail from drm_atomic_helper_commit+0x168/0x190 drm_atomic_helper_commit from drm_atomic_commit+0xb4/0xe0 drm_atomic_commit from drm_client_modeset_commit_atomic+0x23c/0x27c drm_client_modeset_commit_atomic from drm_client_modeset_commit_locked+0x60/0x1cc drm_client_modeset_commit_locked from drm_client_modeset_commit+0x24/0x40 drm_client_modeset_commit from __drm_fb_helper_restore_fbdev_mode_unlocked+0x9c/0xc4 __drm_fb_helper_restore_fbdev_mode_unlocked from drm_fb_helper_set_par+0x2c/0x3c drm_fb_helper_set_par from fbcon_init+0x3d8/0x550 fbcon_init from visual_init+0xc0/0x108 visual_init from do_bind_con_driver+0x1b8/0x3a4 do_bind_con_driver from do_take_over_console+0x140/0x1ec do_take_over_console from do_fbcon_takeover+0x70/0xd0 do_fbcon_takeover from fbcon_fb_registered+0x19c/0x1ac fbcon_fb_registered from register_framebuffer+0x190/0x21c register_framebuffer from __drm_fb_helper_initial_config_and_unlock+0x350/0x574 __drm_fb_helper_initial_config_and_unlock from exynos_drm_fbdev_client_hotplug+0x6c/0xb0 exynos_drm_fbdev_client_hotplug from drm_client_register+0x58/0x94 drm_client_register from exynos_drm_bind+0x160/0x190 exynos_drm_bind from try_to_bring_up_aggregate_device+0x200/0x2d8 try_to_bring_up_aggregate_device from __component_add+0xb0/0x170 __component_add from mixer_probe+0x74/0xcc mixer_probe from platform_probe+0x5c/0xb8 platform_probe from really_probe+0xe0/0x3d8 really_probe from __driver_probe_device+0x9c/0x1e4 __driver_probe_device from driver_probe_device+0x30/0xc0 driver_probe_device from __device_attach_driver+0xa8/0x120 __device_attach_driver from bus_for_each_drv+0x80/0xcc bus_for_each_drv from __device_attach+0xac/0x1fc __device_attach from bus_probe_device+0x8c/0x90 bus_probe_device from deferred_probe_work_func+0x98/0xe0 deferred_probe_work_func from process_one_work+0x240/0x6d0 process_one_work from worker_thread+0x1a0/0x3f4 worker_thread from kthread+0x104/0x138 kthread fro openEuler评分: 3.9 Vector:CVSS:2.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L 受影响版本排查(受影响/不受影响): 1.openEuler-24.03-LTS(6.6.0):受影响 2.openEuler-20.03-LTS-SP4(4.19.90):不受影响 3.openEuler-22.03-LTS-SP1(5.10.0):不受影响 4.openEuler-22.03-LTS-SP3(5.10.0):不受影响 5.openEuler-22.03-LTS-SP4(5.10.0):不受影响 6.master(6.1.0):不受影响 7.openEuler-24.03-LTS-Next(6.6.0):不受影响 修复是否涉及abi变化(是/否): 1.openEuler-20.03-LTS-SP4(4.19.90):否 2.openEuler-22.03-LTS-SP1(5.10.0):否 3.openEuler-22.03-LTS-SP3(5.10.0):否 4.master(6.1.0):否 5.openEuler-24.03-LTS(6.6.0):否 6.openEuler-24.03-LTS-Next(6.6.0):否 7.openEuler-22.03-LTS-SP4(5.10.0):否 三、漏洞修复 安全公告链接:https://www.openeuler.org/zh/security/safety-bulletin/detail/?id=openEuler-SA-2024-1897
一、漏洞信息 漏洞编号:[CVE-2024-40916](https://nvd.nist.gov/vuln/detail/CVE-2024-40916) 漏洞归属组件:[kernel](https://gitee.com/src-openeuler/kernel) 漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.0,6.1.14,6.1.19,6.1.5,6.1.6,6.1.8,6.4.0,6.6.0 CVSS V2.0分值: BaseScore:0.0 Low Vector:CVSS:2.0/ 漏洞简述: In the Linux kernel, the following vulnerability has been resolved:drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID foundWhen reading EDID fails and driver reports no modes available, the DRMcore adds an artificial 1024x786 mode to the connector. Unfortunatelysome variants of the Exynos HDMI (like the one in Exynos4 SoCs) are notable to drive such mode, so report a safe 640x480 mode instead of nothingin case of the EDID reading failure.This fixes the following issue observed on Trats2 board since commit13d5b040363c ( drm/exynos: do not return negative values from .get_modes() ):[drm] Exynos DRM: using 11c00000.fimd device for DMA mapping operationsexynos-drm exynos-drm: bound 11c00000.fimd (ops fimd_component_ops)exynos-drm exynos-drm: bound 12c10000.mixer (ops mixer_component_ops)exynos-dsi 11c80000.dsi: [drm:samsung_dsim_host_attach] Attached s6e8aa0 device (lanes:4 bpp:24 mode-flags:0x10b)exynos-drm exynos-drm: bound 11c80000.dsi (ops exynos_dsi_component_ops)exynos-drm exynos-drm: bound 12d00000.hdmi (ops hdmi_component_ops)[drm] Initialized exynos 1.1.0 20180330 for exynos-drm on minor 1exynos-hdmi 12d00000.hdmi: [drm:hdmiphy_enable.part.0] *ERROR* PLL could not reach steady statepanel-samsung-s6e8aa0 11c80000.dsi.0: ID: 0xa2, 0x20, 0x8cexynos-mixer 12c10000.mixer: timeout waiting for VSYNC------------[ cut here ]------------WARNING: CPU: 1 PID: 11 at drivers/gpu/drm/drm_atomic_helper.c:1682 drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8[CRTC:70:crtc-1] vblank wait timed outModules linked in:CPU: 1 PID: 11 Comm: kworker/u16:0 Not tainted 6.9.0-rc5-next-20240424 #14913Hardware name: Samsung Exynos (Flattened Device Tree)Workqueue: events_unbound deferred_probe_work_funcCall trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x68/0x88 dump_stack_lvl from __warn+0x7c/0x1c4 __warn from warn_slowpath_fmt+0x11c/0x1a8 warn_slowpath_fmt from drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8 drm_atomic_helper_wait_for_vblanks.part.0 from drm_atomic_helper_commit_tail_rpm+0x7c/0x8c drm_atomic_helper_commit_tail_rpm from commit_tail+0x9c/0x184 commit_tail from drm_atomic_helper_commit+0x168/0x190 drm_atomic_helper_commit from drm_atomic_commit+0xb4/0xe0 drm_atomic_commit from drm_client_modeset_commit_atomic+0x23c/0x27c drm_client_modeset_commit_atomic from drm_client_modeset_commit_locked+0x60/0x1cc drm_client_modeset_commit_locked from drm_client_modeset_commit+0x24/0x40 drm_client_modeset_commit from __drm_fb_helper_restore_fbdev_mode_unlocked+0x9c/0xc4 __drm_fb_helper_restore_fbdev_mode_unlocked from drm_fb_helper_set_par+0x2c/0x3c drm_fb_helper_set_par from fbcon_init+0x3d8/0x550 fbcon_init from visual_init+0xc0/0x108 visual_init from do_bind_con_driver+0x1b8/0x3a4 do_bind_con_driver from do_take_over_console+0x140/0x1ec do_take_over_console from do_fbcon_takeover+0x70/0xd0 do_fbcon_takeover from fbcon_fb_registered+0x19c/0x1ac fbcon_fb_registered from register_framebuffer+0x190/0x21c register_framebuffer from __drm_fb_helper_initial_config_and_unlock+0x350/0x574 __drm_fb_helper_initial_config_and_unlock from exynos_drm_fbdev_client_hotplug+0x6c/0xb0 exynos_drm_fbdev_client_hotplug from drm_client_register+0x58/0x94 drm_client_register from exynos_drm_bind+0x160/0x190 exynos_drm_bind from try_to_bring_up_aggregate_device+0x200/0x2d8 try_to_bring_up_aggregate_device from __component_add+0xb0/0x170 __component_add from mixer_probe+0x74/0xcc mixer_probe from platform_probe+0x5c/0xb8 platform_probe from really_probe+0xe0/0x3d8 really_probe from __driver_probe_device+0x9c/0x1e4 __driver_probe_device from driver_probe_device+0x30/0xc0 driver_probe_device from __device_attach_driver+0xa8/0x120 __device_attach_driver from bus_for_each_drv+0x80/0xcc bus_for_each_drv from __device_attach+0xac/0x1fc __device_attach from bus_probe_device+0x8c/0x90 bus_probe_device from deferred_probe_work_func+0---truncated--- 漏洞公开时间:2024-07-12 21:15:14 漏洞创建时间:2024-07-13 16:02:05 漏洞详情参考链接: https://nvd.nist.gov/vuln/detail/CVE-2024-40916 <details> <summary>更多参考(点击展开)</summary> | 参考来源 | 参考链接 | 来源链接 | | ------- | -------- | -------- | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | | | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | | | suse_bugzilla | http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-40916 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://www.cve.org/CVERecord?id=CVE-2024-40916 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | suse_bugzilla | https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-40916.mbox | https://bugzilla.suse.com/show_bug.cgi?id=1227846 | | ubuntu | https://www.cve.org/CVERecord?id=CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/linus/799d4b392417ed6889030a5b2335ccb6dcf030ab (6.10-rc4) | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://nvd.nist.gov/vuln/detail/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://launchpad.net/bugs/cve/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | ubuntu | https://security-tracker.debian.org/tracker/CVE-2024-40916 | https://ubuntu.com/security/CVE-2024-40916 | | debian | | https://security-tracker.debian.org/tracker/CVE-2024-40916 | </details> 漏洞分析指导链接: https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md 漏洞数据来源: openBrain开源漏洞感知系统 漏洞补丁信息: <details> <summary>详情(点击展开)</summary> | 影响的包 | 修复版本 | 修复补丁 | 问题引入补丁 | 来源 | | ------- | -------- | ------- | -------- | --------- | | linux | | https://git.kernel.org/linus/799d4b392417ed6889030a5b2335ccb6dcf030ab | https://git.kernel.org/linus/1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 | ubuntu | </details> 二、漏洞分析结构反馈 影响性分析说明: In the Linux kernel, the following vulnerability has been resolved:drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID foundWhen reading EDID fails and driver reports no modes available, the DRMcore adds an artificial 1024x786 mode to the connector. Unfortunatelysome variants of the Exynos HDMI (like the one in Exynos4 SoCs) are notable to drive such mode, so report a safe 640x480 mode instead of nothingin case of the EDID reading failure.This fixes the following issue observed on Trats2 board since commit13d5b040363c ("drm/exynos: do not return negative values from .get_modes()"):[drm] Exynos DRM: using 11c00000.fimd device for DMA mapping operationsexynos-drm exynos-drm: bound 11c00000.fimd (ops fimd_component_ops)exynos-drm exynos-drm: bound 12c10000.mixer (ops mixer_component_ops)exynos-dsi 11c80000.dsi: [drm:samsung_dsim_host_attach] Attached s6e8aa0 device (lanes:4 bpp:24 mode-flags:0x10b)exynos-drm exynos-drm: bound 11c80000.dsi (ops exynos_dsi_component_ops)exynos-drm exynos-drm: bound 12d00000.hdmi (ops hdmi_component_ops)[drm] Initialized exynos 1.1.0 20180330 for exynos-drm on minor 1exynos-hdmi 12d00000.hdmi: [drm:hdmiphy_enable.part.0] *ERROR* PLL could not reach steady statepanel-samsung-s6e8aa0 11c80000.dsi.0: ID: 0xa2, 0x20, 0x8cexynos-mixer 12c10000.mixer: timeout waiting for VSYNC------------[ cut here ]------------WARNING: CPU: 1 PID: 11 at drivers/gpu/drm/drm_atomic_helper.c:1682 drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8[CRTC:70:crtc-1] vblank wait timed outModules linked in:CPU: 1 PID: 11 Comm: kworker/u16:0 Not tainted 6.9.0-rc5-next-20240424 #14913Hardware name: Samsung Exynos (Flattened Device Tree)Workqueue: events_unbound deferred_probe_work_funcCall trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x68/0x88 dump_stack_lvl from __warn+0x7c/0x1c4 __warn from warn_slowpath_fmt+0x11c/0x1a8 warn_slowpath_fmt from drm_atomic_helper_wait_for_vblanks.part.0+0x2b0/0x2b8 drm_atomic_helper_wait_for_vblanks.part.0 from drm_atomic_helper_commit_tail_rpm+0x7c/0x8c drm_atomic_helper_commit_tail_rpm from commit_tail+0x9c/0x184 commit_tail from drm_atomic_helper_commit+0x168/0x190 drm_atomic_helper_commit from drm_atomic_commit+0xb4/0xe0 drm_atomic_commit from drm_client_modeset_commit_atomic+0x23c/0x27c drm_client_modeset_commit_atomic from drm_client_modeset_commit_locked+0x60/0x1cc drm_client_modeset_commit_locked from drm_client_modeset_commit+0x24/0x40 drm_client_modeset_commit from __drm_fb_helper_restore_fbdev_mode_unlocked+0x9c/0xc4 __drm_fb_helper_restore_fbdev_mode_unlocked from drm_fb_helper_set_par+0x2c/0x3c drm_fb_helper_set_par from fbcon_init+0x3d8/0x550 fbcon_init from visual_init+0xc0/0x108 visual_init from do_bind_con_driver+0x1b8/0x3a4 do_bind_con_driver from do_take_over_console+0x140/0x1ec do_take_over_console from do_fbcon_takeover+0x70/0xd0 do_fbcon_takeover from fbcon_fb_registered+0x19c/0x1ac fbcon_fb_registered from register_framebuffer+0x190/0x21c register_framebuffer from __drm_fb_helper_initial_config_and_unlock+0x350/0x574 __drm_fb_helper_initial_config_and_unlock from exynos_drm_fbdev_client_hotplug+0x6c/0xb0 exynos_drm_fbdev_client_hotplug from drm_client_register+0x58/0x94 drm_client_register from exynos_drm_bind+0x160/0x190 exynos_drm_bind from try_to_bring_up_aggregate_device+0x200/0x2d8 try_to_bring_up_aggregate_device from __component_add+0xb0/0x170 __component_add from mixer_probe+0x74/0xcc mixer_probe from platform_probe+0x5c/0xb8 platform_probe from really_probe+0xe0/0x3d8 really_probe from __driver_probe_device+0x9c/0x1e4 __driver_probe_device from driver_probe_device+0x30/0xc0 driver_probe_device from __device_attach_driver+0xa8/0x120 __device_attach_driver from bus_for_each_drv+0x80/0xcc bus_for_each_drv from __device_attach+0xac/0x1fc __device_attach from bus_probe_device+0x8c/0x90 bus_probe_device from deferred_probe_work_func+0x98/0xe0 deferred_probe_work_func from process_one_work+0x240/0x6d0 process_one_work from worker_thread+0x1a0/0x3f4 worker_thread from kthread+0x104/0x138 kthread fro openEuler评分: 3.9 Vector:CVSS:2.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L 受影响版本排查(受影响/不受影响): 1.openEuler-24.03-LTS(6.6.0):受影响 2.openEuler-20.03-LTS-SP4(4.19.90):不受影响 3.openEuler-22.03-LTS-SP1(5.10.0):不受影响 4.openEuler-22.03-LTS-SP3(5.10.0):不受影响 5.openEuler-22.03-LTS-SP4(5.10.0):不受影响 6.master(6.1.0):不受影响 7.openEuler-24.03-LTS-Next(6.6.0):不受影响 修复是否涉及abi变化(是/否): 1.openEuler-20.03-LTS-SP4(4.19.90):否 2.openEuler-22.03-LTS-SP1(5.10.0):否 3.openEuler-22.03-LTS-SP3(5.10.0):否 4.master(6.1.0):否 5.openEuler-24.03-LTS(6.6.0):否 6.openEuler-24.03-LTS-Next(6.6.0):否 7.openEuler-22.03-LTS-SP4(5.10.0):否 三、漏洞修复 安全公告链接:https://www.openeuler.org/zh/security/safety-bulletin/detail/?id=openEuler-SA-2024-1897
Comments (
8
)
Sign in
to comment
Status
Done
Backlog
已挂起
Doing
Done
Declined
Assignees
Not set
Labels
CVE/FIXED
sig/Kernel
Not set
Projects
Unprojected
Unprojected
Pull Requests
None yet
None yet
Successfully merging a pull request will close this issue.
Branches
No related branch
Branches (
-
)
Tags (
-
)
Planed to start   -   Planed to end
-
Top level
Not Top
Top Level: High
Top Level: Medium
Top Level: Low
Priority
Not specified
Serious
Main
Secondary
Unimportant
Duration
(hours)
参与者(2)
1
https://gitee.com/src-openeuler/kernel.git
git@gitee.com:src-openeuler/kernel.git
src-openeuler
kernel
kernel
Going to Help Center
Search
Git 命令在线学习
如何在 Gitee 导入 GitHub 仓库
Git 仓库基础操作
企业版和社区版功能对比
SSH 公钥设置
如何处理代码冲突
仓库体积过大,如何减小?
如何找回被删除的仓库数据
Gitee 产品配额说明
GitHub仓库快速导入Gitee及同步更新
什么是 Release(发行版)
将 PHP 项目自动发布到 packagist.org
Comment
Repository Report
Back to the top
Login prompt
This operation requires login to the code cloud account. Please log in before operating.
Go to login
No account. Register