Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #86907 > unrolled thread
| Started by | Hideki Yamane <henrich@debian.org> |
|---|---|
| First post | 2025-04-16 00:50 +0200 |
| Last post | 2025-05-07 20:10 +0200 |
| Articles | 4 — 4 participants |
Back to article view | Back to linux.debian.kernel
Bug#1103277: linux: CVE-2024-38541 for 6.1 branch Hideki Yamane <henrich@debian.org> - 2025-04-16 00:50 +0200
Bug#1103277: linux: CVE-2024-38541 for 6.1 branch Salvatore Bonaccorso <carnil@debian.org> - 2025-04-16 06:00 +0200
Bug#1103277: [PATCH 6.1.y] of: module: add buffer overflow check in of_modalias() Uwe Kleine-König <ukleinek@debian.org> - 2025-04-25 16:00 +0200
Bug#1103277: marked as done (linux: CVE-2024-38541 for 6.1 branch) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-05-07 20:10 +0200
| From | Hideki Yamane <henrich@debian.org> |
|---|---|
| Date | 2025-04-16 00:50 +0200 |
| Subject | Bug#1103277: linux: CVE-2024-38541 for 6.1 branch |
| Message-ID | <KBXgl-dNPS-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Source: linux Version: 6.1.133-1 Severity: normal X-Debbugs-Cc: henrich@debian.org Dear Maintainers, I've investigated CVE-2024-38541 since I'm running Debian 12 instances on AWS and Amazon Inspector alerts it is critical vuln. It seems that it is easily applied to 6.1 branch with some modification as attached patch. I've already sent it to original author and reviewer but not get any reply, so I'm maybe wrong... Anyway, could you check it, please? Thank you.
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2025-04-16 06:00 +0200 |
| Message-ID | <KC26l-dQW0-3@gated-at.bofh.it> |
| In reply to | #86907 |
# wontfix unless fixed usptream in 6.1.y series Control: tags -1 + wontfix Hi Hideki On Wed, Apr 16, 2025 at 07:38:54AM +0900, Hideki Yamane wrote: > Source: linux > Version: 6.1.133-1 > Severity: normal > X-Debbugs-Cc: henrich@debian.org > > Dear Maintainers, > > I've investigated CVE-2024-38541 since I'm running Debian 12 instances > on AWS and Amazon Inspector alerts it is critical vuln. > > It seems that it is easily applied to 6.1 branch with some modification > as attached patch. I've already sent it to original author and reviewer > but not get any reply, so I'm maybe wrong... Can you elaborate why you think the AWS and Amazon Inspector are correct and it is a critical vunrablity? Context: https://www.debian.org/security/faq#cve-severity-assessment The last time we got the very same question on the security team for CVE-2024-38541: | On Mon, Mar 31, 2025 at 01:13:59PM -0700, [...] wrote: | > Hi, | > | > I am wondering if the following CVE's fixed in trixie/sid will be | > backported to bullseye and bookworm? | > | > https://security-tracker.debian.org/tracker/CVE-2024-38541 | > https://security-tracker.debian.org/tracker/CVE-2024-38564 | > https://security-tracker.debian.org/tracker/CVE-2024-50061 | | CVE-2024-50061 is already fixed in the latest Bookworm point release. | | For the other two, if you want to see them fixed, you can work | with the maintainers of the 6.1.x LTS kernel tree to accept a | backport: | https://github.com/torvalds/linux/blob/master/Documentation/process/stable-kernel-rules.rst | | The subsequent Debian update will then pick up the fix since we follow | the 6.1.x series. The reason you do not ge a reply might be related to a change in upstream linux done around 18th October 2024. Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | Uwe Kleine-König <ukleinek@debian.org> |
|---|---|
| Date | 2025-04-25 16:00 +0200 |
| Subject | Bug#1103277: [PATCH 6.1.y] of: module: add buffer overflow check in of_modalias() |
| Message-ID | <KFrKV-g9Iu-11@gated-at.bofh.it> |
| In reply to | #86907 |
From: Sergey Shtylyov <s.shtylyov@omp.ru>
[ Upstream commit cf7385cb26ac4f0ee6c7385960525ad534323252 ]
In of_modalias(), if the buffer happens to be too small even for the 1st
snprintf() call, the len parameter will become negative and str parameter
(if not NULL initially) will point beyond the buffer's end. Add the buffer
overflow check after the 1st snprintf() call and fix such check after the
strlen() call (accounting for the terminating NUL char).
Fixes: bc575064d688 ("of/device: use of_property_for_each_string to parse compatible strings")
Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Link: https://lore.kernel.org/r/bbfc6be0-c687-62b6-d015-5141b93f313e@omp.ru
Signed-off-by: Rob Herring <robh@kernel.org>
Signed-off-by: Uwe Kleine-König <ukleinek@debian.org>
---
Hello,
commit cf7385cb26ac4f0ee6c7385960525ad534323252 was already backported to
stable/linux-6.6.y as commit 0b0d5701a8bf02f8fee037e81aacf6746558bfd6.
In 6.1 the function to fix is in a different file and differently named
since v6.1 lacks commits 5c3d15e127eb ("of: Update
of_device_get_modalias()") and bd7a7ed774af ("of: Move of_modalias() to
module.c")
This is the respective backport to 6.1. Looking into that commit was
triggered by https://bugs.debian.org/1103277 and my backport is
identical to this bug's reporter's. Thanks for considering it for the
next 6.1.y update.
Best regards
Uwe
drivers/of/device.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/of/device.c b/drivers/of/device.c
index ce225d2590b5..91d92bfe5735 100644
--- a/drivers/of/device.c
+++ b/drivers/of/device.c
@@ -264,14 +264,15 @@ static ssize_t of_device_get_modalias(struct device *dev, char *str, ssize_t len
csize = snprintf(str, len, "of:N%pOFn%c%s", dev->of_node, 'T',
of_node_get_device_type(dev->of_node));
tsize = csize;
+ if (csize >= len)
+ csize = len > 0 ? len - 1 : 0;
len -= csize;
- if (str)
- str += csize;
+ str += csize;
of_property_for_each_string(dev->of_node, "compatible", p, compat) {
csize = strlen(compat) + 1;
tsize += csize;
- if (csize > len)
+ if (csize >= len)
continue;
csize = snprintf(str, len, "C%s", compat);
base-commit: 535ec20c50273d81b2cc7985fed2108dee0e65d7
--
2.47.2
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2025-05-07 20:10 +0200 |
| Subject | Bug#1103277: marked as done (linux: CVE-2024-38541 for 6.1 branch) |
| Message-ID | <KJRnr-1qqD-13@gated-at.bofh.it> |
| In reply to | #86907 |
[Multipart message — attachments visible in raw view] — view raw
Your message dated Wed, 07 May 2025 18:02:26 +0000 with message-id <E1uCj6A-00EMBJ-1A@fasolo.debian.org> and subject line Bug#1103277: fixed in linux 6.1.137-1 has caused the Debian Bug report #1103277, regarding linux: CVE-2024-38541 for 6.1 branch to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1103277: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1103277 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web