In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() During the v3 firmware download the controller send…
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() During the v3 firmware download the controller sends a v3_data_req with a 32 bit offset and a 16 bit len. nxp_recv_fw_req_v3() checks only the lower bound of the offset and then sends firmware from that offset. nxpdev->fw_dnld_v3_offset = offset - nxpdev->fw_v3_offset_correction; serdev_device_write_buf(nxpdev->serdev, nxpdev->fw->data + …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/21e60eb4d95854196e7c0e77383f35e7ac95df61
- https://git.kernel.org/stable/c/2a68a773089204af1c8581dc79668b775418c5ee
- https://git.kernel.org/stable/c/441088792ffec3ca01f4efe2934060570eb11eb8
- https://git.kernel.org/stable/c/49bcb39e3a041ce26021f77971eaccb49a275118
- https://git.kernel.org/stable/c/badff6c3bed8923a1257a853f137d447976eec30
Timeline
- nvd_ingest NVD