Executive brief
A vulnerability in the Linux kernel's power management component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue exists in the way the system reports frequency transition statistics to users. If the data generated by the system is larger than expected, it can overflow internal memory buffers, leading to instability or security breaches.
Technical details
A buffer overflow exists in the 'trans_stat_show' function within 'drivers/devfreq/devfreq.c' of the Linux kernel. The vulnerability is caused by the use of 'sprintf' without adequate bounds checking when generating the frequency transition table for sysfs. If the number of device frequency states is large enough, the output can exceed the PAGE_SIZE (typically 4KB) limit of the buffer provided by the sysfs interface. An attacker with local access to read the 'trans_stat' sysfs node can trigger this overflow. The fix involves replacing 'sprintf' with 'scnprintf' and implementing explicit checks to ensure the output does not exceed PAGE_SIZE, returning -EFBIG if the buffer is insufficient.
Affected products
- Linux Linux Kernel 3.8 to 5.10.215, 5.11 to 5.15.148, 5.16 to 6.1.75, 6.2 to 6.6.14, 6.7 to 6.7.2
Timeline
- 2023-10-24: other: Initial patch submitted to mailing list
- 2024-03-18: disclosed: CVE published
- 2024-05-02: patched: Final stable branch commits applied
References
- https://git.kernel.org/stable/c/087de000e4f8c878c81d9dd3725f00a1d292980c
- https://git.kernel.org/stable/c/08e23d05fa6dc4fc13da0ccf09defdd4bbc92ff4
- https://git.kernel.org/stable/c/796d3fad8c35ee9df9027899fb90ceaeb41b958f
- https://git.kernel.org/stable/c/8a7729cda2dd276d7a3994638038fb89035b6f2c
- https://git.kernel.org/stable/c/a979f56aa4b93579cf0e4265ae04d7e9300fd3e8
- https://git.kernel.org/stable/c/eaef4650fa2050147ca25fd7ee43bc0082e03c87
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html