• 公告ID (KylinSec-SA-2024-2161)

摘要:

In the Linux kernel, the following vulnerability has been resolved:

regmap: spi: Reserve space for register address/padding

Currently the max_raw_read and max_raw_write limits in regmap_spi struct
do not take into account the additional size of the transmitted register
address and padding. This may result in exceeding the maximum permitted
SPI message size, which could cause undefined behaviour, e.g. data
corruption.

Fix regmap_get_spi_bus() to properly adjust the above mentioned limits
by reserving space for the register address/padding as set in the regmap
configuration.

安全等级: Low

公告ID: KylinSec-SA-2024-2161

发布日期: 2024年5月28日

关联CVE: CVE-2022-48696  

  • 详细介绍

1. 漏洞描述

   

In the Linux kernel, the following vulnerability has been resolved:

regmap: spi: Reserve space for register address/padding

Currently the max_raw_read and max_raw_write limits in regmap_spi struct
do not take into account the additional size of the transmitted register
address and padding. This may result in exceeding the maximum permitted
SPI message size, which could cause undefined behaviour, e.g. data
corruption.

Fix regmap_get_spi_bus() to properly adjust the above mentioned limits
by reserving space for the register address/padding as set in the regmap
configuration.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-48696 KY3.4-4A kernel Unaffected
CVE-2022-48696 KY3.4-5A kernel Unaffected
CVE-2022-48696 KY3.5.1 kernel Unaffected
CVE-2022-48696 KY3.5.3 kernel Unaffected
CVE-2022-48696 V6 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-2160 下一篇:KylinSec-SA-2024-2162