In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpected TREs When a remote device sends a completion event to the host, it contains …
High CVSS 8.4
Summary
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpected TREs When a remote device sends a completion event to the host, it contains a pointer to the consumed TRE. The host uses this pointer to process all of the TREs between it and the host's local copy of the ring's read pointer. This works when processing completion for chained transactions, but can lead to nasty results if the device sends an event for a single-element transa…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/2ec99b922f4661521927eeada76f431eebfbabc4 Patch
- https://git.kernel.org/stable/c/4079c6c59705b96285219b9efc63cab870d757b7 Patch
- https://git.kernel.org/stable/c/44e1a079e18f78d6594a715b0c6d7e18c656f7b9 Patch
- https://git.kernel.org/stable/c/5bd398e20f0833ae8a1267d4f343591a2dd20185 Patch
- https://git.kernel.org/stable/c/5e17429679a8545afe438ce7a82a13a54e8ceabb Patch
- https://git.kernel.org/stable/c/7b3f0e3b60c27f4fcb69927d84987e5fd6240530 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Timeline
- nvd_ingest NVD