Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 week, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/log: Fix out-of-bounds read on empty message length

In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read. Add an early return when len is 0.

Affected products

Linux
  • =<*
  • ==6.14
  • <6.14
  • <16bcea56f4205314ec2aa04a7ec74e5261d253c7
  • <60baa179ed1333535f6e2da4133511db55278ee4
  • =<6.18.*
  • =<7.1.*
  • <16a2716910ecf7d31bf3c033ee7c506a0b00b2ee