Executive brief
A vulnerability exists in the Linux kernel's driver for Realtek RTL2830 digital TV receivers. An error in how the system filters broadcast signals could allow a local user to write data outside of intended memory boundaries. This could potentially lead to a system crash or allow an attacker to gain elevated privileges on the affected device.
Technical details
An out-of-bounds write vulnerability exists in drivers/media/dvb-frontends/rtl2830.c within the rtl2830_pid_filter function. The issue stems from an incorrect boundary check where the code allowed an index of 32 to be used on a 32-bit bitmask (dev->filters). Because bit indices are zero-based (0-31), an index of 32 results in an out-of-bounds access when calling set_bit or clear_bit. A local attacker with access to the DVB device could exploit this to corrupt kernel memory, potentially leading to a denial of service or local privilege escalation. The fix changes the boundary check from 'index > 32' to 'index >= 32'.
Affected products
- Linux Linux Kernel 4.0 to 4.19.323, 4.20 to 5.4.285, 5.5 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2
Timeline
- 2024-07-03: other: Vulnerability fixed in source code
- 2024-10-21: disclosed: CVE published
References
- https://git.kernel.org/stable/c/042b101d7bf70616c4967c286ffa6fcca65babfb
- https://git.kernel.org/stable/c/3dba83d3c81de1368d15a39f22df7b53e306052f
- https://git.kernel.org/stable/c/46d7ebfe6a75a454a5fa28604f0ef1491f9d8d14
- https://git.kernel.org/stable/c/58f31be7dfbc0c84a6497ad51924949cf64b86a2
- https://git.kernel.org/stable/c/7fd6aae7e53b94f4035b1bfce28b8dfa0d0ae470
- https://git.kernel.org/stable/c/86d920d2600c3a48efc2775c1666c1017eec6956
- https://git.kernel.org/stable/c/883f794c6e498ae24680aead55c16f66b06cfc30