In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Ensure array index tg_inst won't be -1 [WHY & HOW] tg_inst will… (CVE-2024-46730)
A medium-severity vulnerability in the Linux kernel's AMD display driver (drm/amd/display) was resolved. The issue involved the array index tg_inst potentially being -1 when timing_generator_count is zero, leading to two overrun conditions. This flaw was detected by Coverity and fixed by adding a check to prevent negative indexing.
AI Analysis
Technical Summary
The vulnerability CVE-2024-46730 in the Linux kernel's AMD display component arises because the variable tg_inst can become -1 if timing_generator_count equals zero. Using tg_inst as an array index without validation leads to two buffer overrun issues. The fix ensures timing_generator_count is checked before tg_inst is used, preventing negative indexing and associated overruns.
Potential Impact
The vulnerability can cause buffer overruns in the AMD display driver, potentially leading to denial of service (crash) due to corrupted memory. The CVSS score of 5.5 reflects a medium severity with local attack vector, low complexity, requiring low privileges and no user interaction. There is no impact on confidentiality or integrity, only availability.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to check timing_generator_count before using tg_inst as an array index, preventing negative indexing and overruns. Users should update to the patched Linux kernel version containing this fix. No additional mitigation steps are indicated.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Ensure array index tg_inst won't be -1 [WHY & HOW] tg_inst will… (CVE-2024-46730)
Description
A medium-severity vulnerability in the Linux kernel's AMD display driver (drm/amd/display) was resolved. The issue involved the array index tg_inst potentially being -1 when timing_generator_count is zero, leading to two overrun conditions. This flaw was detected by Coverity and fixed by adding a check to prevent negative indexing.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2024-46730 in the Linux kernel's AMD display component arises because the variable tg_inst can become -1 if timing_generator_count equals zero. Using tg_inst as an array index without validation leads to two buffer overrun issues. The fix ensures timing_generator_count is checked before tg_inst is used, preventing negative indexing and associated overruns.
Potential Impact
The vulnerability can cause buffer overruns in the AMD display driver, potentially leading to denial of service (crash) due to corrupted memory. The CVSS score of 5.5 reflects a medium severity with local attack vector, low complexity, requiring low privileges and no user interaction. There is no impact on confidentiality or integrity, only availability.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to check timing_generator_count before using tg_inst as an array index, preventing negative indexing and overruns. Users should update to the patched Linux kernel version containing this fix. No additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g4xf-vj7c-7443
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2024-46730"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac13969a43b0b3b89d5fbb5
Added to database: 10/03/2026, 17:20:41 UTC
Last enriched: 10/03/2026, 17:24:07 UTC
Last updated: 10/04/2026, 02:45:59 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.