Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
dm-ioctl: fix a possible overflow in list_version_get_info

In the Linux kernel, the following vulnerability has been resolved: dm-ioctl: fix a possible overflow in list_version_get_info sizeof(tt->version) is 12 bytes, but the code writes 16 bytes into the output buffer - info->vers->version[0], info->vers->version[1], info->vers->version[2] and info->vers->next. This can cause buffer overflow. Fix this buffer overflow by replacing "sizeof(tt->version)" with "sizeof(struct dm_target_versions)".

Affected products

Linux
  • <76c6f845dc0c614304a6e6ee619b552f97cf24b3
  • <29536a9ff146d9bbd618959857ed2e691cda1d21
  • <d61c12573ed9768690fdcb2bc38846a1bcb01358
  • =<6.6.*
  • =<*
  • <7.1.5
  • <6.12.97
  • <6.18.40
  • =<6.18.*
  • =<6.12.*
  • =<7.1.*
  • <df50c24c6447c18886ed126d3d81cc7e155ea8b6
  • <6.6.145
  • <e0f5842c4e2a7dbefb52a2dc6711789bc6963e55