Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 day, 4 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
firmware: arm_scmi: Fix OOB in scmi_power_name_get()

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix OOB in scmi_power_name_get() scmi_power_name_get() does not validate the domain number passed by the external caller, which may lead to an out-of-bounds access. Fix this by returning "unknown" for invalid domains, like scmi_reset_name_get() does.

Affected products

Linux
  • =<6.1.*
  • <11daac2817dca75e3eabb2050bc620c29e686fcd
  • <0db2bb3c948ef8b7364768554d6ab5e1544dc441
  • =<6.18.*
  • <30aa348494531adfb043b2e883afc0439e5fcdca
  • =<6.12.*
  • =<7.1.*
  • <11bb771f3c55b4cef3879e69da4ddecd6085569c
  • <4.17
  • =<5.15.*
  • =<6.6.*
  • <f9ef3f66f4b18078e464b7606f9497e4dbeb9905
  • =<*
  • <01613f5e4ff6c080260615392338e92e261d109b
  • ==4.17
  • <ca94597440fa546e56293abe9d0af6c73535d44e