Bug 1222538 (CVE-2024-26730) - VUL-0: CVE-2024-26730: kernel: hwmon: (nct6775) Fix access to temperature configuration registers
Summary: VUL-0: CVE-2024-26730: kernel: hwmon: (nct6775) Fix access to temperature con...
Status: RESOLVED FIXED
Alias: CVE-2024-26730
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/400223/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-26730:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-09 11:01 UTC by SMASH SMASH
Modified: 2024-04-09 11:06 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-04-09 11:01:21 UTC
In the Linux kernel, the following vulnerability has been resolved:

hwmon: (nct6775) Fix access to temperature configuration registers

The number of temperature configuration registers does
not always match the total number of temperature registers.
This can result in access errors reported if KASAN is enabled.

BUG: KASAN: global-out-of-bounds in nct6775_probe+0x5654/0x6fe9 nct6775_core

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-26730
https://www.cve.org/CVERecord?id=CVE-2024-26730
https://git.kernel.org/stable/c/c196387820c9214c5ceaff56d77303c82514b8b1
https://git.kernel.org/stable/c/d56e460e19ea8382f813eb489730248ec8d7eb73
https://git.kernel.org/stable/c/f006c45a3ea424f8f6c8e4b9283bc245ce2a4d0f
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-26730.mbox
https://bugzilla.redhat.com/show_bug.cgi?id=2273254
Comment 1 Alexander Bergmann 2024-04-09 11:04:22 UTC
Only affecting kernel 6.6. Closing as not affected.