Executive brief
A vulnerability in the Linux kernel's device management system could allow a local user to trigger an out-of-bounds memory read. This occurs when the system processes hardware interrupt information for certain devices. An exploit could lead to a system crash or the exposure of sensitive kernel memory, potentially impacting system stability and data confidentiality.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's Device Tree (OF) interrupt parsing logic. Specifically, in `of_irq_parse_raw()`, if a device address is smaller than the interrupt parent node's `#address-cells` property, the kernel may read past the allocated buffer for the device address. This was identified via KASAN (Kernel Address Sanitizer) during interrupt map walks. A local attacker with the ability to trigger device tree parsing (e.g., via overlays or specific hardware interactions) could exploit this to read sensitive kernel memory or cause a denial of service (system crash). The fix involves copying the device address into a sufficiently sized buffer before processing.
Affected products
- Linux Linux Kernel up to (excluding) 4.19.322, 4.20 to (excluding) 5.4.284, 5.5 to (excluding) 5.10.226, 5.11 to (excluding) 5.15.167, 5.16 to (excluding) 6.1.110, 6.2 to (excluding) 6.6.51, 6.7 to (excluding) 6.10.10, 6.11-rc1
Timeline
- 2024-08-12: other: Patch authored
- 2024-09-12: patched: Patch committed to stable tree
- 2024-09-18: disclosed: CVE published
References
- https://git.kernel.org/stable/c/7ead730af11ee7da107f16fc77995613c58d292d
- https://git.kernel.org/stable/c/8ff351ea12e918db1373b915c4c268815929cbe5
- https://git.kernel.org/stable/c/9d1e9f0876b03d74d44513a0ed3ed15ef8f2fed5
- https://git.kernel.org/stable/c/b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305
- https://git.kernel.org/stable/c/baaf26723beab3a04da578d3008be3544f83758f
- https://git.kernel.org/stable/c/bf68acd840b6a5bfd3777e0d5aaa204db6b461a9
- https://git.kernel.org/stable/c/d2a79494d8a5262949736fb2c3ac44d20a51b0d8