固件:cs_dsp:处理块之前验证有效载荷长度(CVE-2024-42237)

admin 2024-08-10 12:27:01 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
固件:cs_dsp:处理块之前验证有效载荷长度(CVE-2024-42237)

CVE编号

CVE-2024-42237

利用情况

暂无

补丁情况

N/A

披露时间

2024-08-08
漏洞描述
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_load() and cs_dsp_coeff_load() to be done before the block is processed. The check that the length of a block payload does not exceed the number of remaining bytes in the firwmware file buffer was being done near the end of the loop iteration. However, some code before that check used the length field without validating it.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://git.kernel.org/stable/c/259955eca9b7acf1299b1ac077d8cfbe12df35d8
https://git.kernel.org/stable/c/3a9cd924aec1288d675df721f244da4dd7e16cff
https://git.kernel.org/stable/c/6598afa9320b6ab13041616950ca5f8f938c0cf1
https://git.kernel.org/stable/c/71d9e313d8f7e18c543a9c80506fe6b1eb1fe0c8
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 debian_11 linux * Up to (excluding) 5.10.221-1
运行在以下环境
系统 linux linux_kernel * Up to (excluding) 5.16
运行在以下环境
系统 linux linux_kernel * From (including) 5.17 Up to (excluding) 6.1.100
运行在以下环境
系统 linux linux_kernel * From (including) 6.2 Up to (excluding) 6.6.41
运行在以下环境
系统 linux linux_kernel * From (including) 6.7 Up to (excluding) 6.9.10
CVSS3评分 5.5
  • 攻击路径 本地
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 高
  • 保密性 无
  • 完整性 无
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-ID 漏洞类型
CWE-834 过度迭代
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0