Back

MEDIUM

phy: marvell: a3700-comphy: Fix out of bounds read

Published May 20, 2024

Description

There is an out of bounds read access of 'gbe_phy_init_fix[fix_idx].addr' every iteration after 'fix_idx' reaches 'ARRAY_SIZE(gbe_phy_init_fix)'.

Make sure 'gbe_phy_init[addr]' is used when all elements of 'gbe_phy_init_fix' array are handled.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

Remediation

Red Hat statement

The phy-mvebu-a3700-comphy module is not built in the kernel shipped in Red Hat Enterprise Linux, so it is not affected by this vulnerability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 20, 2024
Updated May 11, 2026
Reserved May 17, 2024
CISA Vulnrichment
Updated May 20, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 20, 2024