dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it uses the size of copy_from_user to copy a userspace buffer into a 40-byte heap buffer.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-21T00:00:00

Updated: 2024-08-04T03:30:38.271Z

Reserved: 2021-10-12T00:00:00

Link: CVE-2021-42327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-21T17:15:07.913

Modified: 2024-03-25T01:15:51.437

Link: CVE-2021-42327

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-10-13T00:00:00Z

Links: CVE-2021-42327 - Bugzilla