Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38552

21
FAUCET Score

CVE-2024-38552 is a high-severity vulnerability in the Linux kernel's AMD display driver, specifically affecting the color transformation function. It involves an index out-of-bounds error (CWE-129) that could lead to buffer overflows when the index 'i' exceeds the number of transfer function points. With a CVSS score of 7.8, this local vulnerability (AV:L) could result in high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.16, < 4.19.316CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.278CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.219CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.93CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 58th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch

Vendor Advisories (3)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-38552Low

kernel: drm/amd/display: Fix potential index out of bounds in color transformation function

Jun 19, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/04bc4d1090c343025d69149ca669a27c5b9c34a7
Patch
git.kernel.org / stable/c/123edbae64f4d21984359b99c6e79fcde31c6123
Patch
git.kernel.org / stable/c/4e8c8b37ee84b3b19c448d2b8e4c916d2f5b9c86
Patch
git.kernel.org / stable/c/604c506ca43fce52bb882cff9c1fdf2ec3b4029c
Patch
git.kernel.org / stable/c/63ae548f1054a0b71678d0349c7dc9628ddd42ca
Patch
git.kernel.org / stable/c/7226ddf3311c5e5a7726ad7d4e7b079bb3cfbb29
Patch
git.kernel.org / stable/c/98b8a6bfd30d07a19cfacdf82b50f84bf3360869
Patch
git.kernel.org / stable/c/ced9c4e2289a786b8fa684d8893b7045ea53ef7e
Patch
git.kernel.org / stable/c/e280ab978c81443103d7c61bdd1d8d708cf6ed6d
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00020.html