Back

HIGH

i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()

Published Apr 28, 2024

Description

memcpy() is called in a loop while 'operation->length' upper bound is not checked and 'data_idx' also increments.

Affected products

Remediation

Red Hat statement

Actual only for ARM platforms. For the Red Hat Enterprise Linux and Fedora the related code disabled, so not affected (apart from the latest version of the Red Hat Enterprise Linux 9 and latest version of the Red Hat Enterprise Linux 10). The bug could happen only if Mellanox BlueField I2C controller being used.

Red Hat mitigation

To mitigate this issue, prevent module i2c-mlxbf from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Apr 28, 2024
Updated Aug 5, 2026
Reserved Feb 25, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Apr 28, 2024