ALSA: fireworks: bound device-supplied status before string array lookup
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
ALSA: fireworks: bound device-supplied status before string array lookup
The status field in an EFW response is a 32-bit value supplied by the
firewire device. efr_status_names[] has 17 entries so a status value
outside that range goes off into the weeds when looking at the %s value.
Even worse, the status could return EFR_STATUS_INCOMPLETE which is
0x80000000, and is obviously not in that array of potential strings.
Fix this up by properly bounding the index against the array size and
printing "unknown" if it's not recognized.
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/07704bbf36f57e4379e4cadf96410dab14621e3bhttps://git.kernel.org/stable/c/183aa0de0f680496b9feb85c9d182681ad4600ddhttps://git.kernel.org/stable/c/327f8e730e3c65ec97df9d3b07de66aeb3dc932dhttps://git.kernel.org/stable/c/62fcb273fbee5b2a0e7ed41cc914c8d7d1a5d285https://git.kernel.org/stable/c/67cfd14074cdafab5de3f7cfc0952c1a9b653e5dhttps://git.kernel.org/stable/c/682d8accf0d83a871e8c327b95c81f53902c922bhttps://git.kernel.org/stable/c/cc624b3d2be13297100539b64ad950695188e046https://git.kernel.org/stable/c/e103f98f6615ed2934e9cf340654f0cad9eb8a8ahttps://git.kernel.org/stable/c/f856f4b6efd51be7950e4b84c06cd961961ca41c