Back

HIGH

iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw

Published Oct 21, 2024

Description

KASAN report out-of-bounds read as follows:

BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380 Read of size 4 at addr ffffffffc00e4658 by task cat/278

Call Trace: afe4404_read_raw iio_read_channel_info dev_attr_show

The buggy address belongs to the variable: afe4404_channel_leds+0x18/0xffffffffffffe9c0

This issue can be reproduce by singe command:

$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw

The array size of afe4404_channel_leds and afe4404_channel_offdacs are less than channels, so access with chan->address cause OOB read in afe4404_[read|write]_raw. Fix it by moving access before use them.

Affected products

Remediation

No remediation recorded yet.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated May 11, 2026
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024
ENISA EUVD
Assigner Linux
Published Oct 21, 2024
Updated May 11, 2026
Exploited since n/a
EUVD-2022-53916