Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 3 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc In sof_ipc3_control_update(), the expected_size calculation uses firmware-provided cdata->num_elems in arithmetic that could overflow on 32-bit platforms, wrapping to a small value. This would allow the cdata->rhdr.hdr.size comparison to pass with mismatched sizes, potentially leading to out-of-bounds access in snd_sof_update_control. Use check_mul_overflow() and check_add_overflow() to detect and reject overflowed size calculations.

Affected products

Linux
  • <5.18
  • <89a2309a9eec80d4c19e3aed62c4f923594d1911
  • <ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3
  • <8791977d7289f6e9d2b014f60a5455f053a7bc04
  • =<6.6.*
  • =<*
  • ==5.18
  • <6856b3c23b0995eefad5a6142b4365ef70e1fe4a
  • <711d912b18763af62a63aa8f2419a774eb63bba4
  • =<6.12.*
  • =<6.18.*
  • =<7.1.*
  • <312c7d2ebe696da3f885eee77d52297664e57c53
  • =<6.1.*