iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw
Published Oct 21, 2024
7.1
HIGHCVSS 3.1
EPSS 0.24%
Description
KASAN report out-of-bounds read as follows:
BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380 Read of size 4 at addr ffffffffc00e4658 by task cat/278
Call Trace: afe4404_read_raw iio_read_channel_info dev_attr_show
The buggy address belongs to the variable: afe4404_channel_leds+0x18/0xffffffffffffe9c0
This issue can be reproduce by singe command:
$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw
The array size of afe4404_channel_leds and afe4404_channel_offdacs are less than channels, so access with chan->address cause OOB read in afe4404_[read|write]_raw. Fix it by moving access before use them.
Affected products
-
- Version b36e8257641aStatusaffectedConstraints<113c08030a89
- Version b36e8257641aStatusaffectedConstraints<3f566b626029
- Version b36e8257641aStatusaffectedConstraints<5eb114f55b37
- Version b36e8257641aStatusaffectedConstraints<68de7da092f3
- Version b36e8257641aStatusaffectedConstraints<d45d9f45e7b1
- Version b36e8257641aStatusaffectedConstraints<f5575041ec15
- Version b36e8257641aStatusaffectedConstraints<f7419fc42afc
- Version b36e8257641aStatusaffectedConstraints<fc92d9e3de0b
- Version
-
- Version 4.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.8
- Version 4.14.301StatusunaffectedConstraints<=4.14.*
- Version 4.19.268StatusunaffectedConstraints<=4.19.*
- Version 4.9.335StatusunaffectedConstraints<=4.9.*
- Version 5.10.158StatusunaffectedConstraints<=5.10.*
- Version 5.15.82StatusunaffectedConstraints<=5.15.*
- Version 5.4.226StatusunaffectedConstraints<=5.4.*
- Version 6.0.12StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.8 · < 4.9.335
- ≥ 4.10 · < 4.14.301
- ≥ 4.15 · < 4.19.268
- ≥ 4.20 · < 5.4.226
- ≥ 5.5 · < 5.10.158
- ≥ 5.11 · < 5.15.82
- ≥ 5.16 · < 6.0.12
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-49032 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320679 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53916 Advisory
- https://git.kernel.org/stable/c/113c08030a89aaf406f8a1d4549d758a67c2afba Patch
- https://git.kernel.org/stable/c/3f566b626029ca8598d48e5074e56bb37399ca1b Patch
- https://git.kernel.org/stable/c/5eb114f55b37dbc0487aa9c1913b81bb7837f1c4 Patch
- https://git.kernel.org/stable/c/68de7da092f38395dde523f2e5db26eba6c23e28 Patch
- https://git.kernel.org/stable/c/d45d9f45e7b1365fd0d9bf14680d6d5082a590d1 Patch
- https://git.kernel.org/stable/c/f5575041ec15310bdc50c42b8b22118cc900226e Patch
- https://git.kernel.org/stable/c/f7419fc42afc035f6b29ce713e17dcd2000c833f Patch
- https://git.kernel.org/stable/c/fc92d9e3de0b2d30a3ccc08048a5fad533e4672b Patch
- https://lore.kernel.org/linux-cve-announce/2024102156-CVE-2022-49032-d2a1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49032
- https://www.cve.org/CVERecord?id=CVE-2022-49032
Change history (0)
No recorded changes yet.