Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/panthor: validate firmware interface structure sizes

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: validate firmware interface structure sizes iface_fw_to_cpu_addr() only checks that the firmware-provided MCU virtual address points inside the shared section. The returned pointer is later used as a full firmware interface structure, so accepting an address near the end of the shared section can still lead to out-of-bounds accesses. Pass the expected object size to iface_fw_to_cpu_addr() and reject ranges that do not fit entirely in the shared section.

Affected products

Linux
  • <21c77486f5a60bb9c0433c21de62a5f25d5091f1
  • <c835f2b0b7167584832b516c9b0a26e9180d1d0b
  • ==6.10
  • =<*
  • <b921b8613790a3f9e78ab64017fa7149ef0b750c
  • =<6.18.*
  • =<6.12.*
  • =<7.1.*
  • <6.10
  • <ca41d9f3a21586bf29df53eec05152ecf2b2f94f