Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
ASoC: tegra: tegra210_ahub: Validate written enum value

In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Validate written enum value tegra_ahub_put_value_enum() reads e->values[item[0]] before checking whether item[0] is within the enum item range. The existing check therefore happens too late to prevent an out-of-range read of the values array. Move the check before the array access.

Affected products

Linux
  • <4e45e4c2015519a39c40eb575c03b77807fb5080
  • <1d8aabb413b5638670dfd1162169edc0ba276a2e
  • ==5.9
  • =<5.10.*
  • <964f8f9015fb117402d8d2186593397cd93388e9
  • <2ec7d16fe21c68b0879873a2abf9aac854c96134
  • =<6.6.*
  • =<*
  • <e098c9c6477dfa3cb363282100108484ceba5cc5
  • <5.9
  • <4bcb23635d5059ee71f3fb89719ea14aada6fd59
  • =<6.18.*
  • =<6.12.*
  • =<7.1.*
  • =<5.15.*
  • <226d93b65f4f99b35fb7a03bdb24acb577364ebc
  • <f67d63628fe158b3a6e6b33a2b8c83ff118699d1
  • =<6.1.*