From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5109084D0B for ; Wed, 1 May 2024 12:57:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1714568278; cv=none; b=Jh1KYSPXqjObR3iqUvzfX0V53v1NJutbfiw2IiOxsDTU2fbA+zz5oQxS8OjZM/lzI1qRzTiFWgkWO1RDHl6UbZX/4KEFzc4ezNtZVJA9tbzdr1ZRh5zW7SLCbQALmxuv4Y/qXlOMoxFAmZckUbmeuaYxcryPSWDrOdB7N+0LG6U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1714568278; c=relaxed/simple; bh=xrMFZ1haVwnI3P6Vc7M0e9POZJzee3spo3d8lJSb52s=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HrsJr5HnoJm8MYTgvZiWGTJjOGntr/bMgg6ml4rhXsipjsP4Q4ECj1Ttd/JcLMhMWW3u44CWF9BMYtOWnRpkgGVxmkr5on/Ge14bseI6Tw7xj3c59X8lIUpgE8Ig58dO1pxUfEW9bmV/YG2Pfi+NY6f490synke+fvyYNyJ+8Is= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=VUSplQa7; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="VUSplQa7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 86107C113CC; Wed, 1 May 2024 12:57:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1714568277; bh=xrMFZ1haVwnI3P6Vc7M0e9POZJzee3spo3d8lJSb52s=; h=From:To:Cc:Subject:Date:Reply-to:From; b=VUSplQa7pomptJgnOXALUPx2pmfyIt8/cgNf/2pBTq+u88RfP21VI+9Zll8hJ03JN CXtMhSWEROvc4+hTYNOxeuLkNwoENKFqs8y8HeJxv3nia9RIV7Uj16hpjG31Q94LuX RVg2JWhiNohkPVMubBIGsERz05IKZJw1joaShsRk= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2023-52651: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() Date: Wed, 1 May 2024 14:57:12 +0200 Message-ID: <2024050110-CVE-2023-52651-5907@gregkh> X-Mailer: git-send-email 2.44.0 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3124; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=xrMFZ1haVwnI3P6Vc7M0e9POZJzee3spo3d8lJSb52s=; b=owGbwMvMwCRo6H6F97bub03G02pJDGlGNmo/dsZkKGezFMWHxMkVLzjCc6HPZI6vjWeic7RLq 9v0XsaOWBYGQSYGWTFFli/beI7urzik6GVoexpmDisTyBAGLk4BmIiBJMM8838aK+rtrVk1FKdN n3aFdbHJF8UJDAuW1Nzj09KQ9D1/oeBI1bzvdk8nCd8GAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() We should check whether the WMI_TLV_TAG_STRUCT_MGMT_TX_COMPL_EVENT tlv is present before accessing it, otherwise a null pointer deference error will occur. The Linux kernel CVE team has assigned CVE-2023-52651 to this issue. Affected and fixed versions =========================== Issue introduced in 4.19 with commit dc405152bb64 and fixed in 4.19.311 with commit 0cd3b0a1dc98 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 5.4.273 with commit 88a9dffaec77 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 5.10.214 with commit e1dc7aa814a9 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 5.15.153 with commit 4c4e592266b6 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 6.1.83 with commit 90f089d77e38 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 6.6.23 with commit 10a342fa2fe4 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 6.7.11 with commit db755cf93f58 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 6.8.2 with commit 835c5d37f4b0 Issue introduced in 4.19 with commit dc405152bb64 and fixed in 6.9-rc1 with commit ad25ee36f001 Issue introduced in 4.19.2 with commit aea35bd40d64 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2023-52651 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/wireless/ath/ath10k/wmi-tlv.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0cd3b0a1dc987697cba1fe93c784365aa1f8a230 https://git.kernel.org/stable/c/88a9dffaec779504ab3680d33cf677741c029420 https://git.kernel.org/stable/c/e1dc7aa814a95aeeb1b2c05be2b62af8423b15cc https://git.kernel.org/stable/c/4c4e592266b6eec748ce90e82bd9cbc9838f3633 https://git.kernel.org/stable/c/90f089d77e38db1c48629f111f3c8c336be1bc38 https://git.kernel.org/stable/c/10a342fa2fe4c4dd22f2c8fe917d3b1929582076 https://git.kernel.org/stable/c/db755cf93f5895bbac491d27a8e2fe04c5f9ae4a https://git.kernel.org/stable/c/835c5d37f4b0ba99e9ec285ffa645bc532714191 https://git.kernel.org/stable/c/ad25ee36f00172f7d53242dc77c69fff7ced0755