Executive brief
A vulnerability in the Linux kernel's I2C/SMBus component could allow a local user to cause a system crash. The issue occurs when certain hardware controllers are used in 'target-only' mode, leading to a kernel panic (OOPS). This affects the availability of the system but does not directly expose sensitive data.
Technical details
A NULL pointer dereference exists in the Linux kernel's I2C core (specifically in drivers/i2c/i2c-core-base.c). The vulnerability is triggered when an I2C controller, such as the DesignWare controller, is configured in target-only mode. In this configuration, the 'master_xfer' function pointer may be NULL, but the kernel previously assumed a transfer function would always be available. An attacker with local access could trigger this NULL dereference via the __i2c_transfer function, resulting in a kernel OOPS and denial of service. The fix involves adding a mandatory check for the master_xfer pointer before use. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.19 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9
Timeline
- 2024-04-26: patched: Initial patch authored by Wolfram Sang
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/357c64ef1ef39b1e7cd91ab6bdd304d043702c83
- https://git.kernel.org/stable/c/40f1d79f07b49c8a64a861706e5163f2db4bd95d
- https://git.kernel.org/stable/c/4e75e222d397c6752b229ed72fc4644c8c36ecde
- https://git.kernel.org/stable/c/5a09eae9a7db597fe0c1fc91636205b4a25d2620
- https://git.kernel.org/stable/c/5fd72404587d7db4acb2d241fd8c387afb0a7aec
- https://git.kernel.org/stable/c/91811a31b68d3765b3065f4bb6d7d6d84a7cfc9f
- https://git.kernel.org/stable/c/ad3c3ac7a03be3697114f781193dd3e9d97e6e23