power: supply: gpio-charger: Fix set charge current limits
Published Jan 11, 2025
7.8
HIGHCVSS 3.1
EPSS 0.26%
Description
Fix set charge current limits for devices which allow to set the lowest charge current limit to be greater zero. If requested charge current limit is below lowest limit, the index equals current_limit_map_size which leads to accessing memory beyond allocated memory.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.10
- Version 5.10.233StatusunaffectedConstraints<=5.10.*
- Version 5.15.176StatusunaffectedConstraints<=5.15.*
- Version 6.1.123StatusunaffectedConstraints<=6.1.*
- Version 6.12.8StatusunaffectedConstraints<=6.12.*
- Version 6.13StatusunaffectedConstraints<=*
- Version 6.6.69StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.10 · < 5.10.233
- ≥ 5.11 · < 5.15.176
- ≥ 5.16 · < 6.1.123
- ≥ 6.2 · < 6.6.69
- ≥ 6.7 · < 6.12.8
- 6.13
- 6.13
- 6.13
- 6.13
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (13)
- https://access.redhat.com/security/cve/CVE-2024-57792 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2337114 Issue Tracking
- https://git.kernel.org/stable/c/13eb3cae1d8e23cce96c095abe34da8028c09ac5 Patch
- https://git.kernel.org/stable/c/6abbbd8286b6f944eecf3c74444c138590135211 Patch
- https://git.kernel.org/stable/c/afc6e39e824ad0e44b2af50a97885caec8d213d1 Patch
- https://git.kernel.org/stable/c/b29c7783ac1fe36d639c089cf471ac7a46df05f0 Patch
- https://git.kernel.org/stable/c/c3703d9340ca2820e1ac63256f4b423ea8559831 Patch
- https://git.kernel.org/stable/c/f6279a98db132da0cfff18712a1b06478c32007f Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lore.kernel.org/linux-cve-announce/2025011150-CVE-2024-57792-0002@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-57792
- https://www.cve.org/CVERecord?id=CVE-2024-57792
Change history (0)
No recorded changes yet.