iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
0Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Track
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].
When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.
Fix by using sizeof(*lstat) to clear only the target entry.
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fahttps://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407bhttps://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a