Bug 1225028 (CVE-2023-52794) - VUL-0: CVE-2023-52794: kernel: thermal: intel: powerclamp: fix mismatch in get function for max_idle
Summary: VUL-0: CVE-2023-52794: kernel: thermal: intel: powerclamp: fix mismatch in ge...
Status: RESOLVED INVALID
Alias: CVE-2023-52794
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/407121/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-52794:3.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-05-22 14:52 UTC by SMASH SMASH
Modified: 2024-07-08 15:01 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-05-22 14:52:16 UTC
In the Linux kernel, the following vulnerability has been resolved:

thermal: intel: powerclamp: fix mismatch in get function for max_idle

KASAN reported this

      [ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90
      [ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105
      ...
      [ 444.853442] The buggy address belongs to the variable:
      [ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp]

There is a mismatch between the param_get_int and the definition of
max_idle.  Replacing param_get_int with param_get_byte resolves this
issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52794
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2023/CVE-2023-52794.mbox
https://git.kernel.org/stable/c/6a3866dbdcf39ac93e98708e6abced511733dc18
https://git.kernel.org/stable/c/0a8585281b11e3a0723bba8d8085d61f0b55f37c
https://git.kernel.org/stable/c/fae633cfb729da2771b5433f6b84ae7e8b4aa5f7
https://www.cve.org/CVERecord?id=CVE-2023-52794
Comment 2 Carlos López 2024-05-28 09:50:39 UTC
Nothing to do, closing.