In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer length data->block[0] is validated in i2…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer length data->block[0] is validated in i2c_smbus_xfer_emulated() but that check runs too late for tracepoints and is skipped entirely when the adapter provides a native smbus_xfer implementation. This allows user-controlled oversized block lengths to reach tracepoint memcpy calls and driver callbacks unchecked. Add an early validation in …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/3051cd060fa496df42954291fa2306ed2eab4ecc
- https://git.kernel.org/stable/c/c4b478bc50b7ca9865e237909941253a0f7111a2
- https://git.kernel.org/stable/c/f09edffba97d37b1fdff5f818a9a45f8a98ac171
Timeline
- nvd_ingest NVD