usb: typec: altmodes/displayport: validate count before reading Status Update VDO
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: altmodes/displayport: validate count before reading Status Update VDO
A broken/malicious device can send the incorrect count for a status
update VDO, which will cause the kernel to read uninitialized stack data
and send it off elsewhere.
Fix this up by correctly verifying the count for the update object.
Productos afectados
Linux · LinuxReferencias
https://git.kernel.org/stable/c/64bd6ccc5799f8473d1f37d4d8f53093dfec5c02https://git.kernel.org/stable/c/6ffdbcd7a02f3af8fff9b6519830369f574ed44chttps://git.kernel.org/stable/c/70e7045849e954e56dcbf441b6330e66bc996306https://git.kernel.org/stable/c/74aabe9ea30fdfba924fce9594e6aa69a596a4bbhttps://git.kernel.org/stable/c/77a759ec30bc5fb0dd9c867b711d0acfed6c7faahttps://git.kernel.org/stable/c/8a18f896e667df491331371b55d4ad644dc51d60https://git.kernel.org/stable/c/b10eff5abe6aa2a5af10ed17bddff76e3b6e6b9bhttps://git.kernel.org/stable/c/dd7118c010f324497c275e8fd7a35c9baaa2a00f