[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025022621-CVE-2022-49218-26ee@gregkh>
Date: Wed, 26 Feb 2025 02:57:03 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
Subject: CVE-2022-49218: drm/dp: Fix OOB read when handling Post Cursor2 register
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
drm/dp: Fix OOB read when handling Post Cursor2 register
The link_status array was not large enough to read the Adjust Request
Post Cursor2 register, so remove the common helper function to avoid
an OOB read, found with a -Warray-bounds build:
drivers/gpu/drm/drm_dp_helper.c: In function 'drm_dp_get_adjust_request_post_cursor':
drivers/gpu/drm/drm_dp_helper.c:59:27: error: array subscript 10 is outside array bounds of 'const u8[6]' {aka 'const unsigned char[6]'} [-Werror=array-bounds]
59 | return link_status[r - DP_LANE0_1_STATUS];
| ~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~
drivers/gpu/drm/drm_dp_helper.c:147:51: note: while referencing 'link_status'
147 | u8 drm_dp_get_adjust_request_post_cursor(const u8 link_status[DP_LINK_STATUS_SIZE],
| ~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Replace the only user of the helper with an open-coded fetch and decode,
similar to drivers/gpu/drm/amd/display/dc/core/dc_link_dp.c.
The Linux kernel CVE team has assigned CVE-2022-49218 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.5 with commit 79465e0ffeb9e4866939ea562bc55367be91e595 and fixed in 5.17.2 with commit aeaed9a9fe694f8b1462fb81e2d33298c929180b
Issue introduced in 5.5 with commit 79465e0ffeb9e4866939ea562bc55367be91e595 and fixed in 5.18 with commit a2151490cc6c57b368d7974ffd447a8b36ade639
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2022-49218
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/gpu/drm/dp/drm_dp.c
drivers/gpu/drm/tegra/dp.c
include/drm/dp/drm_dp_helper.h
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/aeaed9a9fe694f8b1462fb81e2d33298c929180b
https://git.kernel.org/stable/c/a2151490cc6c57b368d7974ffd447a8b36ade639
Powered by blists - more mailing lists