• 公告ID (KylinSec-SA-2024-2097)

摘要:

In the Linux kernel, the following vulnerability has been resolved:

clk: qcom: camcc-sc8280xp: fix terminating of frequency table arrays

The frequency table arrays are supposed to be terminated with an
empty element. Add such entry to the end of the arrays where it
is missing in order to avoid possible out-of-bound access when
the table is traversed by functions like qcom_find_freq() or
qcom_find_freq_floor().

Only compile tested.

安全等级: Low

公告ID: KylinSec-SA-2024-2097

发布日期: 2024年5月28日

关联CVE: CVE-2024-26967  

  • 详细介绍

1. 漏洞描述

   

In the Linux kernel, the following vulnerability has been resolved:

clk: qcom: camcc-sc8280xp: fix terminating of frequency table arrays

The frequency table arrays are supposed to be terminated with an
empty element. Add such entry to the end of the arrays where it
is missing in order to avoid possible out-of-bound access when
the table is traversed by functions like qcom_find_freq() or
qcom_find_freq_floor().

Only compile tested.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-26967 KY3.4-4A kernel Unaffected
CVE-2024-26967 KY3.4-5 kernel Unaffected
CVE-2024-26967 KY3.5.1 kernel Unaffected
CVE-2024-26967 KY3.5.3 kernel Unaffected
CVE-2024-26967 V6 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-2096 下一篇:KylinSec-SA-2024-2098