Path: csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Hideki Yamane Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#1103277: linux: CVE-2024-38541 for 6.1 branch Date: Wed, 16 Apr 2025 00:50:01 +0200 Message-ID: X-Original-To: Debian Bug Tracking System X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Tue Apr 15 22:42:10 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -4.2 Reply-To: Hideki Yamane , 1103277@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: henrich@debian.org, Debian Kernel Team X-Debian-Pr-Message: report 1103277 X-Debian-Pr-Package: src:linux X-Debian-Pr-Source: linux Content-Type: multipart/mixed; boundary="===============3686246520965025345==" MIME-Version: 1.0 X-Mailer: reportbug 13.1.0 X-Debian-Message: from BTS X-Mailing-List: archive/latest/1899620 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 87 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Wed, 16 Apr 2025 07:38:54 +0900 X-Original-Message-ID: <174475673466.780068.1015713546824904902.reportbug@t14s> Xref: csiph.com linux.debian.bugs.dist:1242209 linux.debian.kernel:86907 This is a multi-part MIME message sent by reportbug. --===============3686246520965025345== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline Source: linux Version: 6.1.133-1 Severity: normal X-Debbugs-Cc: henrich@debian.org Dear Maintainers, I've investigated CVE-2024-38541 since I'm running Debian 12 instances on AWS and Amazon Inspector alerts it is critical vuln. It seems that it is easily applied to 6.1 branch with some modification as attached patch. I've already sent it to original author and reviewer but not get any reply, so I'm maybe wrong... Anyway, could you check it, please? Thank you. --===============3686246520965025345== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename="0001-of-device-add-buffer-overflow-check-in-of_device_get.patch" From 58c18ebe72c2ff8bce5fbbc8d0a55dde1f264ac4 Mon Sep 17 00:00:00 2001 From: Hideki Yamane Date: Fri, 28 Mar 2025 17:24:08 +0900 Subject: [PATCH] of: device: add buffer overflow check in of_device_get_modalias() (CVE-2024-38541) [ Upstream commit cf7385cb26ac4f0ee6c7385960525ad534323252 ] > In of_modalias(), if the buffer happens to be too small even for the 1st > snprintf() call, the len parameter will become negative and str parameter > (if not NULL initially) will point beyond the buffer's end. Add the buffer > overflow check after the 1st snprintf() call and fix such check after the > strlen() call (accounting for the terminating NUL char). > > Fixes: bc575064d688 ("of/device: use of_property_for_each_string to parse compatible strings") > Signed-off-by: Sergey Shtylyov > Link: https://lore.kernel.org/r/bbfc6be0-c687-62b6-d015-5141b93f313e@omp.ru > Signed-off-by: Rob Herring drivers/of/module.c was splited from drivers/of/device.c, so same fix can be applied to device.c. --- drivers/of/device.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/of/device.c b/drivers/of/device.c index ce225d2590b5..91d92bfe5735 100644 --- a/drivers/of/device.c +++ b/drivers/of/device.c @@ -264,14 +264,15 @@ static ssize_t of_device_get_modalias(struct device *dev, char *str, ssize_t len csize = snprintf(str, len, "of:N%pOFn%c%s", dev->of_node, 'T', of_node_get_device_type(dev->of_node)); tsize = csize; + if (csize >= len) + csize = len > 0 ? len - 1 : 0; len -= csize; - if (str) - str += csize; + str += csize; of_property_for_each_string(dev->of_node, "compatible", p, compat) { csize = strlen(compat) + 1; tsize += csize; - if (csize > len) + if (csize >= len) continue; csize = snprintf(str, len, "C%s", compat); -- 2.47.2 --===============3686246520965025345==--