Note:
This project will be discontinued after December 13, 2021. [more]
2020-04-29
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
Products | Linux_kernel, Active_iq_unified_manager, Aff_baseboard_management_controller, Cloud_backup, Hci_baseboard_management_controller, Hci_compute_node, Solidfire_\&_hci_management_node, Solidfire_baseboard_management_controller, Steelstore_cloud_integrated_storage |
Type | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120) |
First patch | - None (likely due to unavailable code) |
Patches |
• https://github.com/torvalds/linux/commit/b102f0c522cf668c8382c56a4f771b37d011cda2
• https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2 |
Links |
• https://security.netapp.com/advisory/ntap-20200608-0001/
• https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10 |