Bug 1215069 (CVE-2023-21636)

Summary: VUL-0: CVE-2023-21636: kernel-source-azure,kernel-source-rt,kernel-source: Memory Corruption due to improper validation of array index in Linux while updating adn record.
Product: [Novell Products] SUSE Security Incidents Reporter: Cathy Hu <cathy.hu>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED INVALID QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: cathy.hu, jlee, pmladek, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/377231/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Cathy Hu 2023-09-06 12:05:11 UTC
CVE-2023-21636

Memory Corruption due to improper validation of array index in Linux while
updating adn record.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-21636
https://www.cve.org/CVERecord?id=CVE-2023-21636
https://www.qualcomm.com/company/product-security/bulletins/september-2023-bulletin
Comment 2 Joey Lee 2023-09-07 04:13:30 UTC
It does no have enough information for kernel. Does it only affect Qualcomm chips?
Comment 3 Cathy Hu 2023-09-07 10:02:11 UTC
i think so (at least from searching on the internet)

i will email the qualcomm people for clarification
Comment 4 Petr Mladek 2023-09-15 09:16:19 UTC
Cathy, have you got any feedback from Qualcomm, please?
Comment 7 Petr Mladek 2023-09-18 07:53:46 UTC
Assigning back to the security team for further tracking. I am not sure if we want to close the bug or it has to me mentioned in some security advisory.
Comment 8 Cathy Hu 2023-09-18 08:11:09 UTC
closing should suffice :)