From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DAE8722606 for ; Fri, 23 Feb 2024 14:48:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708699695; cv=none; b=DtERKh+FDTdgjfYo3yPF80p6hjEhH29+KFPYYVlgZnEP4e4wTWi1cqHr17tYc2Q4QmlwPTdbcU8cUh0U9WwLQOGr1sRiUte/YPoHQTdQ9no8O09LGMd5KwfgK+w3LOtEWLD2OOfyum7+p3xaYrwfe6H0QrXbwic8veaHKL6AJ5s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708699695; c=relaxed/simple; bh=uzqZnPmD8Cf3WTiBidIQUNxinx2LWqoZkKpQV7/8CQU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ulzgp4ZBUMYniFQYbKV6Gi55xqTlnAdmBMj5KOboV1PnM6QR1GEgCUOz+KhFz8+VE7kSlBGHpQmlC4bnLefh/gPGP7oS30vvjLJN54txhrJyyY0ncKgJTNbQylhyX/t3cL46y2VmhyyrbyYGq9kpO+xJzf91w+c4KjlnJM5fZMw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=d/pRWqsN; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="d/pRWqsN" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 26CAEC433C7; Fri, 23 Feb 2024 14:48:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1708699695; bh=uzqZnPmD8Cf3WTiBidIQUNxinx2LWqoZkKpQV7/8CQU=; h=From:To:Cc:Subject:Date:Reply-to:From; b=d/pRWqsNlN7KZ4ZlU4FzT4VcQzh3QWsunH+sTZJrRQDeG3jsnb/t0R5opIATmUOwT KeZ5wkWnt6LO6RT0KswRicNqBAYhSb5WgFBkQQoxDzKJEKIX8H7Zr0fIkaqmKKqaQW SP4tAL8IVB1MZAcRzdQiuh0DnyaudOGv2HsxMJF8= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2023-52464: EDAC/thunderx: Fix possible out-of-bounds string access Date: Fri, 23 Feb 2024 15:47:36 +0100 Message-ID: <2024022336-CVE-2023-52464-b17c@gregkh> X-Mailer: git-send-email 2.43.2 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3700; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=uzqZnPmD8Cf3WTiBidIQUNxinx2LWqoZkKpQV7/8CQU=; b=owGbwMvMwCRo6H6F97bub03G02pJDKk3NnCcbLj/PjJ3gyabhSnv0j1H876pGc3fnR8pm/PWd 1d/e8vnjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIy88MC1YJdj4Q+6O58TRT ss9SrvpvrQd+OzAsaKwPLfd/EfLXodXvRyDHl2cHqo4FAwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: EDAC/thunderx: Fix possible out-of-bounds string access Enabling -Wstringop-overflow globally exposes a warning for a common bug in the usage of strncat(): drivers/edac/thunderx_edac.c: In function 'thunderx_ocx_com_threaded_isr': drivers/edac/thunderx_edac.c:1136:17: error: 'strncat' specified bound 1024 equals destination size [-Werror=stringop-overflow=] 1136 | strncat(msg, other, OCX_MESSAGE_SIZE); | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ... 1145 | strncat(msg, other, OCX_MESSAGE_SIZE); ... 1150 | strncat(msg, other, OCX_MESSAGE_SIZE); ... Apparently the author of this driver expected strncat() to behave the way that strlcat() does, which uses the size of the destination buffer as its third argument rather than the length of the source buffer. The result is that there is no check on the size of the allocated buffer. Change it to strlcat(). [ bp: Trim compiler output, fixup commit message. ] The Linux kernel CVE team has assigned CVE-2023-52464 to this issue. Affected and fixed versions =========================== Issue introduced in 4.12 with commit 41003396f932 and fixed in 4.19.306 with commit 71c17ee02538 Issue introduced in 4.12 with commit 41003396f932 and fixed in 5.4.268 with commit 5da3b6e7196f Issue introduced in 4.12 with commit 41003396f932 and fixed in 5.10.209 with commit 6aa7865ba7ff Issue introduced in 4.12 with commit 41003396f932 and fixed in 5.15.148 with commit 700cf4bead80 Issue introduced in 4.12 with commit 41003396f932 and fixed in 6.1.75 with commit 9dbac9fdae6e Issue introduced in 4.12 with commit 41003396f932 and fixed in 6.6.14 with commit e1c865112415 Issue introduced in 4.12 with commit 41003396f932 and fixed in 6.7.2 with commit 426fae93c01d Issue introduced in 4.12 with commit 41003396f932 and fixed in 6.8-rc1 with commit 475c58e1a471 Please see https://www.kernel.org or a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2023-52464 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/edac/thunderx_edac.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/71c17ee02538802ceafc830f0736aa35b564e601 https://git.kernel.org/stable/c/5da3b6e7196f0b4f3728e4e25eb20233a9ddfaf6 https://git.kernel.org/stable/c/6aa7865ba7ff7f0ede0035180fb3b9400ceb405a https://git.kernel.org/stable/c/700cf4bead80fac994dcc43ae1ca5d86d8959b21 https://git.kernel.org/stable/c/9dbac9fdae6e3b411fc4c3fca3bf48f70609c398 https://git.kernel.org/stable/c/e1c86511241588efffaa49556196f09a498d5057 https://git.kernel.org/stable/c/426fae93c01dffa379225eb2bd4d3cdc42c6eec5 https://git.kernel.org/stable/c/475c58e1a471e9b873e3e39958c64a2d278275c8