kernel: i2c: out-of-bounds write in xgene_slimpro_i2c_xfer()
Published Apr 20, 2023
6.7
MEDIUMCVSS 3.1
EPSS 0.24%
Description
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Affected products
- Vendor n/a Product Linux kernel: i2c: xgene-slimpro Defaultunknown
Affected
- Fixed in kernel v6.3-rc4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Linux kernel: i2c: xgene-slimpro | unknown | Affected
|
Configuration 1
- < 6.3
- 6.3
- 6.3
- 6.3
Configuration 2
- 38
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.21.1.el8_8
Fixed · RHSA-2023:4517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-477.21.1.rt7.284.el8_8
Fixed · RHSA-2023:4541
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.18.1.el9_2
Fixed · RHSA-2023:3723
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.18.1.el9_2
Fixed · RHSA-2023:3723
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.18.1.rt14.303.el9_2
Fixed · RHSA-2023:3708
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.21.1.el8_8 | Fixed | RHSA-2023:4517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-477.21.1.rt7.284.el8_8 | Fixed | RHSA-2023:4541 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.18.1.el9_2 | Fixed | RHSA-2023:3723 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.18.1.el9_2 | Fixed | RHSA-2023:3723 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.18.1.rt14.303.el9_2 | Fixed | RHSA-2023:3708 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6 and 7 are not affected by this vulnerability as the shipped kernels did not include support for SLIMpro I2C device driver (upstream commit f6505fb). This flaw was rated Moderate as i2c devices are root-only accessible in RHEL.
Red Hat mitigation
This flaw can be mitigated by preventing the i2c-xgene-slimpro module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from being loaded automatically.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-2194 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2188396 Issue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-33709 Advisory
- https://github.com/torvalds/linux/commit/92fbb6d1296f Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2023-2194
- https://www.cve.org/CVERecord?id=CVE-2023-2194
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-2194 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2188396 | Issue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-33709 | Advisory | |
| https://github.com/torvalds/linux/commit/92fbb6d1296f | Patch | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html | mailing-list | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-2194 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-2194 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data