Wind River Support Network

HomeDefectsLIN1024-3262
Fixed

LIN1024-3262 : Security Advisory - linux - CVE-2024-42130

Created: Jul 30, 2024    Updated: Aug 28, 2024
Resolved Date: Jul 30, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

nfc/nci: Add the inconsistency check between the input data length and count

write$nci(r0, &(0x7f0000000740)=ANY=@ANYBLOB="610501"], 0xf)

Syzbot constructed a write() call with a data length of 3 bytes but a count value
of 15, which passed too little data to meet the basic requirements of the function
nci_rf_intf_activated_ntf_packet().

Therefore, increasing the comparison between data length and count value to avoid
problems caused by inconsistent data length and count.

CREATE(Triage):(User=admin) [CVE-2024-42130 (https://nvd.nist.gov/vuln/detail/CVE-2024-42130)

CVEs


Live chat
Online