Executive brief
A vulnerability in the Linux kernel's driver for the DP83869 Ethernet hardware can cause system memory corruption when fiber optic connections are enabled. This could allow a local user to cause a system crash or unpredictable behavior, potentially leading to a denial of service. The issue affects systems using specific Texas Instruments Ethernet physical layer (PHY) hardware.
Technical details
A memory corruption vulnerability exists in the Linux kernel DP83869 PHY driver within the dp83869_configure_fiber function. The driver incorrectly calls linkmode_set_bit() using a bit mask (1 << 10) instead of a bit number (10) for the ADVERTISED_FIBRE flag. This results in an out-of-bounds write that corrupts adjacent memory locations, such as the 'priv' pointer within the phy_device structure on arm64 architectures. An attacker with local access could exploit this to cause a kernel panic or denial of service. The fix involves removing the redundant and incorrect bit setting, as advertising flags are properly updated later in the configuration process.
Affected products
- Linux Linux Kernel 5.10 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.57, 6.7 to 6.11.4, 6.12-rc1, 6.12-rc2
Timeline
- 2024-10-03: patched: Initial fix committed to mainline kernel.
- 2024-11-08: disclosed: CVE-2024-50188 published.
References
- https://git.kernel.org/stable/c/21b5af7f0c99b3bf1fd02016e6708b613acbcaf4
- https://git.kernel.org/stable/c/9ca634676ff66e1d616259e136f96f96b2a1759a
- https://git.kernel.org/stable/c/a842e443ca8184f2dc82ab307b43a8b38defd6a5
- https://git.kernel.org/stable/c/ad0d76b8ee5db063791cc2e7a30ffc9852ac37c4
- https://git.kernel.org/stable/c/c1944b4253649fc6f2fb53e7d6302eb414d2182c
- https://git.kernel.org/stable/c/e3f2de32dae35bc7d173377dc97b5bc9fcd9fc84
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html