drm/nouveau: fix off by one in BIOS boundary checking
Published Jun 20, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Bounds checking when parsing init scripts embedded in the BIOS reject access to the last byte. This causes driver initialization to fail on Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working console.
This is probably only seen on OpenFirmware machines like PowerPC Macs because the BIOS image provided by OF is only the used parts of the ROM, not a power-of-two blocks read from PCI directly so PCs always have empty bytes at the end that are never accessed.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.8
- Version 4.14.265StatusunaffectedConstraints<=4.14.*
- Version 4.19.228StatusunaffectedConstraints<=4.19.*
- Version 4.9.300StatusunaffectedConstraints<=4.9.*
- Version 5.10.99StatusunaffectedConstraints<=5.10.*
- Version 5.15.22StatusunaffectedConstraints<=5.15.*
- Version 5.16.8StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.178StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.8 · < 4.9.300
- ≥ 4.10 · < 4.14.265
- ≥ 4.15 · < 4.19.228
- ≥ 4.20 · < 5.4.178
- ≥ 5.5 · < 5.10.99
- ≥ 5.11 · < 5.15.22
- ≥ 5.16 · < 5.16.8
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has evaluated the impact effects on availability as High, but no impact on Confidentiality or Integrity. This, in conjunction with the permissions level required to exploit this flaw, is best reflected by an overall impact of Low.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-48732 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293327 Issue Tracking
- https://git.kernel.org/stable/c/1b777d4d9e383d2744fc9b3a09af6ec1893c8b1a Patch
- https://git.kernel.org/stable/c/909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2 Patch
- https://git.kernel.org/stable/c/acc887ba88333f5fec49631f12d8cc7ebd95781c Patch
- https://git.kernel.org/stable/c/b2a21669ee98aafc41c6d42ef15af4dab9e6e882 Patch
- https://git.kernel.org/stable/c/d4b746e60fd8eaa8016e144223abe91158edcdad Patch
- https://git.kernel.org/stable/c/d877e814a62b7de9069aeff8bc1d979dfc996e06 Patch
- https://git.kernel.org/stable/c/e7c36fa8a1e63b08312162179c78a0c7795ea369 Patch
- https://git.kernel.org/stable/c/f071d9fa857582d7bd77f4906691f73d3edeab73 Patch
- https://lore.kernel.org/linux-cve-announce/2024062000-CVE-2022-48732-9d9b@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48732
- https://www.cve.org/CVERecord?id=CVE-2022-48732
Change history (0)
No recorded changes yet.