ASoC: tegra: tegra210_ahub: Validate written enum value
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
ASoC: tegra: tegra210_ahub: Validate written enum value
tegra_ahub_put_value_enum() reads e->values[item[0]] before
checking whether item[0] is within the enum item range. The existing
check therefore happens too late to prevent an out-of-range read of the
values array.
Move the check before the array access.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/1d8aabb413b5638670dfd1162169edc0ba276a2ehttps://git.kernel.org/stable/c/226d93b65f4f99b35fb7a03bdb24acb577364ebchttps://git.kernel.org/stable/c/2ec7d16fe21c68b0879873a2abf9aac854c96134https://git.kernel.org/stable/c/4bcb23635d5059ee71f3fb89719ea14aada6fd59https://git.kernel.org/stable/c/4e45e4c2015519a39c40eb575c03b77807fb5080https://git.kernel.org/stable/c/964f8f9015fb117402d8d2186593397cd93388e9https://git.kernel.org/stable/c/e098c9c6477dfa3cb363282100108484ceba5cc5https://git.kernel.org/stable/c/f67d63628fe158b3a6e6b33a2b8c83ff118699d1