CVE-2024-36965
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/06/2024
Last modified:
17/07/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
remoteproc: mediatek: Make sure IPI buffer fits in L2TCM<br />
<br />
The IPI buffer location is read from the firmware that we load to the<br />
System Companion Processor, and it&#39;s not granted that both the SRAM<br />
(L2TCM) size that is defined in the devicetree node is large enough<br />
for that, and while this is especially true for multi-core SCP, it&#39;s<br />
still useful to check on single-core variants as well.<br />
<br />
Failing to perform this check may make this driver perform R/W<br />
operations out of the L2TCM boundary, resulting (at best) in a<br />
kernel panic.<br />
<br />
To fix that, check that the IPI buffer fits, otherwise return a<br />
failure and refuse to boot the relevant SCP core (or the SCP at<br />
all, if this is single core).
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.160 (including) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.92 (including) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.32 (including) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.8.11 (including) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.9 (including) | 6.9.2 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/00548ac6b14428719c970ef90adae2b3b48c0cdf
- https://git.kernel.org/stable/c/1d9e2de24533daca36cbf09e8d8596bf72b526b2
- https://git.kernel.org/stable/c/26c6d7dc8c6a9fde9d362ab2eef6390efeff145e
- https://git.kernel.org/stable/c/331f91d86f71d0bb89a44217cc0b2a22810bbd42
- https://git.kernel.org/stable/c/36c79eb4845551e9f6d28c663b38ce0ab03b84a9
- https://git.kernel.org/stable/c/838b49e211d59fa827ff9df062d4020917cffbdf