ep93xx: clock: Fix off by one in ep93xx_div_recalc_rate()
Published Oct 21, 2024
7.1
HIGHCVSS 3.1
EPSS 0.24%
Description
The psc->div[] array has psc->num_div elements. These values come from when we call clk_hw_register_div(). It's adc_divisors and ARRAY_SIZE(adc_divisors)) and so on. So this condition needs to be >= instead of > to prevent an out of bounds read.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.16
Unaffected
- ≥ 0, < 5.16
- ≥ 6.1.113, ≤ 6.1.*
- ≥ 6.10.13, ≤ 6.10.*
- ≥ 6.11.2, ≤ 6.11.*
- 6.12
- ≥ 6.6.54, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.16 · < 6.1.113
- ≥ 6.2 · < 6.6.54
- ≥ 6.7 · < 6.10.13
- ≥ 6.11 · < 6.11.2
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2024-47686 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320273 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-42606 Advisory
- https://git.kernel.org/stable/c/27f493e141823db052586010c1532b70b164507c Patch
- https://git.kernel.org/stable/c/66e78ade976dbd9bea09166aa8d66afc0963cde4 Patch
- https://git.kernel.org/stable/c/7a5bd2fb92388c51d267f6ce57c40f1cca8af1e0 Patch
- https://git.kernel.org/stable/c/ae59eaf36a1ad396e9f657ec9b8b52da6206ed5f Patch
- https://git.kernel.org/stable/c/c7f06284a6427475e3df742215535ec3f6cd9662 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024102109-CVE-2024-47686-e46a@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-47686
- https://www.cve.org/CVERecord?id=CVE-2024-47686
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data