Back

MEDIUM

kernel: i2c: out-of-bounds write in xgene_slimpro_i2c_xfer()

Published Apr 20, 2023

Description

An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 6 and 7 are not affected by this vulnerability as the shipped kernels did not include support for SLIMpro I2C device driver (upstream commit f6505fb). This flaw was rated Moderate as i2c devices are root-only accessible in RHEL.

Red Hat mitigation

This flaw can be mitigated by preventing the i2c-xgene-slimpro module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from being loaded automatically.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Apr 20, 2023
Updated Apr 23, 2025
Reserved Apr 20, 2023

CISA Vulnrichment

Updated Apr 23, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 16, 2023
Bugzilla 2188396

ENISA EUVD

Assigner redhat
Published Apr 20, 2023
Updated Apr 23, 2025

GitHub

No data