Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
platform/x86: ISST: Validate level in perf mask ioctls

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _read_bf_level_info(), but neither helper validates it first. The adjacent level-info helpers reject levels above max_level before reading the same per-level register block. Add the same bounds checks to the mask helpers, and reject disabled SST-PP levels in isst_if_get_perf_level_mask() to match isst_if_get_perf_level_info(). This prevents out-of-bounds reads from the per-level offset table on invalid ioctl input.

Affected products

Linux
  • <d19385624bdfb577db9c94bb8879992fd5e17bcd
  • <1889a9156553f0692acd57caf15e877baace1a01
  • ==6.4
  • <6.4
  • =<7.2.*
  • =<6.12.*
  • =<6.18.*
  • <1a8bab5ceee1a42a78de12d3d69f67516a20588e
  • <80e0d353c86a9a168ad6d213f494796294381538
  • =<*