phy: marvell: a3700-comphy: Fix out of bounds read
Published May 20, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
There is an out of bounds read access of 'gbe_phy_init_fix[fix_idx].addr' every iteration after 'fix_idx' reaches 'ARRAY_SIZE(gbe_phy_init_fix)'.
Make sure 'gbe_phy_init[addr]' is used when all elements of 'gbe_phy_init_fix' array are handled.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.18
- Version 6.1.90StatusunaffectedConstraints<=6.1.*
- Version 6.6.30StatusunaffectedConstraints<=6.6.*
- Version 6.8.9StatusunaffectedConstraints<=6.8.*
- Version 6.9StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.18 · < 6.1.90
- ≥ 6.2 · < 6.6.30
- ≥ 6.7 · < 6.8.9
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The phy-mvebu-a3700-comphy module is not built in the kernel shipped in Red Hat Enterprise Linux, so it is not affected by this vulnerability.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-35992 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2281841 Issue Tracking
- https://git.kernel.org/stable/c/40406dfbc060503d2e0a9e637e98493c54997b3d Patch
- https://git.kernel.org/stable/c/610f175d2e16fb2436ba7974b990563002c20d07 Patch
- https://git.kernel.org/stable/c/976df695f579bbb2914114b4e9974fe4ed1eb813 Patch
- https://git.kernel.org/stable/c/e4308bc22b9d46cf33165c9dfaeebcf29cd56f04 Patch
- https://lore.kernel.org/linux-cve-announce/2024052020-CVE-2024-35992-2e88@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-35992
- https://www.cve.org/CVERecord?id=CVE-2024-35992
Change history (0)
No recorded changes yet.