Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 day, 13 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing The driver parses CDC union descriptors in ims_pcu_get_cdc_union_desc() by iterating through the extra descriptor data. However, it does not verify that the bLength of each descriptor is at least 2. A malicious device could provide a descriptor with bLength = 0, leading to an infinite loop in the driver. Add a check to ensure bLength is at least 2 before proceeding with parsing.

Affected products

Linux
  • =<6.1.*
  • <76eeeb3a8e3c13d5c0ef28666b57dcb5cc101a32
  • <6314bd9e2a6b3362998dc85485dd4b0f133a3532
  • <d4579af29e67ca8722db0a1194227f8015c8981d
  • =<6.18.*
  • =<5.10.*
  • =<6.6.*
  • =<6.12.*
  • <e3f93d63dcd48c1f0ba9041f2ffa8aea7170e295
  • <bbbe31486cf2d12177462e4a814244c2597c9849
  • =<7.1.*
  • <b847f2725ef47a26b3d01eca3d54fd811e5a544d
  • <383934c249a9817d242d02d30bfbc8defbf0d533
  • =<5.15.*
  • <67a038c5a7c9bd8aabe6fba8ac9d2e31c0bd5a28
  • <3.10
  • =<*
  • ==3.10