PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port()
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
Within kirin_pcie_parse_port(), the pcie->num_slots is compared to pcie->gpio_id_reset size (MAX_PCI_SLOTS) which is correct and would lead to an overflow.
Thus, fix condition to pcie->num_slots + 1 >= MAX_PCI_SLOTS and move pcie->num_slots increment below the if-statement to avoid out-of-bounds array access.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
[kwilczynski: commit log]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.16
- Version 6.1.113StatusunaffectedConstraints<=6.1.*
- Version 6.10.13StatusunaffectedConstraints<=6.10.*
- Version 6.11.2StatusunaffectedConstraints<=6.11.*
- Version 6.12StatusunaffectedConstraints<=*
- Version 6.6.54StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.16 · < 6.1.113
- ≥ 6.2 · < 6.6.54
- ≥ 6.7 · < 6.10.13
- ≥ 6.11 · < 6.11.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2024-47751 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320230 Issue Tracking
- https://git.kernel.org/stable/c/6dcc5b49d6607a741a14122bf3105f3ac50d259e Patch
- https://git.kernel.org/stable/c/95248d7497bcbfe7deed4805469c6ff6ddd7f9d1 Patch
- https://git.kernel.org/stable/c/a5f795f9412854df28e66679c5e6b68b0b79c229 Patch
- https://git.kernel.org/stable/c/aeb0335971806e15ac91e838ca471936c8e7efd5 Patch
- https://git.kernel.org/stable/c/c500a86693a126c9393e602741e348f80f1b0fc5 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024102113-CVE-2024-47751-7a96@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-47751
- https://www.cve.org/CVERecord?id=CVE-2024-47751
Change history (0)
No recorded changes yet.