From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 43204524A5 for ; Fri, 17 May 2024 13:23:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715952229; cv=none; b=nfEpbJJB1qrD8CPpQ+7MlBOn9H2wpX8D4BcXQHz3lwT0pDyIjUsSWVGCMxNg11ma9tQVPv33mJccuQ8HRXZnc9dCDbVyz6vIWLbnqxxmWShxwlT9bNPiY6PlnkFyE3sfvmQbkGrKL0p5kpXNX3vCS/sX8hAiOYXatNnfSJpYIiQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715952229; c=relaxed/simple; bh=Ua+xSxITPPnkRYx2DbgPE/Bj52mzhOSPz7DzJz5dTn0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ltOwMj+UjaCQ+1T9er+n4EZG1/GFbggvWS57iHsTVW0nYrHAJD3QybL65IctbnQysJZROul9wOpVO8ixZYOCeOHBopgQjkuu2ValJ6xwFl5pjonXCKb8Bb3oY+GSPt705T3mrpRpZIw6nhqiF7RAHCduASpXtkN2BOG5Vmf9IUQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=R61ZYAwn; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="R61ZYAwn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 77AEBC2BD10; Fri, 17 May 2024 13:23:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1715952228; bh=Ua+xSxITPPnkRYx2DbgPE/Bj52mzhOSPz7DzJz5dTn0=; h=From:To:Cc:Subject:Date:Reply-to:From; b=R61ZYAwnThXWJJWbrCOJ9kdn0Sr0w3o7m+yUGW6N2TVPKR+FWQjWGiClqjK2xlVwT S/HJp3fPZaCUklDNRdL93y91mo/vzU4vKyOi03xW/dHN11m32Gh50PGceZdwSEVs+J NyecF2v/yFuID8j7bcSLFMeS2uyQgiL1+XIxQamo= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-35796: net: ll_temac: platform_get_resource replaced by wrong function Date: Fri, 17 May 2024 15:23:36 +0200 Message-ID: <2024051736-CVE-2024-35796-e66c@gregkh> X-Mailer: git-send-email 2.45.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2958; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Ua+xSxITPPnkRYx2DbgPE/Bj52mzhOSPz7DzJz5dTn0=; b=owGbwMvMwCRo6H6F97bub03G02pJDGnuUZGHlnk+Zc0zuqf//qP208Svkz8HG9T++f/DX3jfO uevHj8tOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAihmsZFqw/tWl6Vv3Jy5In DniVRagY+231ucEwi2l+xme3zvgnmz4/7Lk015jp1aaljAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: net: ll_temac: platform_get_resource replaced by wrong function The function platform_get_resource was replaced with devm_platform_ioremap_resource_byname and is called using 0 as name. This eventually ends up in platform_get_resource_byname in the call stack, where it causes a null pointer in strcmp. if (type == resource_type(r) && !strcmp(r->name, name)) It should have been replaced with devm_platform_ioremap_resource. The Linux kernel CVE team has assigned CVE-2024-35796 to this issue. Affected and fixed versions =========================== Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 5.10.215 with commit 6d9395ba7f85 Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 5.15.154 with commit 553d294db94b Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 6.1.84 with commit 46efbdbc95a3 Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 6.6.24 with commit 476eed5f1c22 Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 6.7.12 with commit 7e9edb569fd9 Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 6.8.3 with commit 92c0c29f6678 Issue introduced in 5.9 with commit bd69058f50d5 and fixed in 6.9 with commit 3a38a829c8bc Issue introduced in 5.8.2 with commit 77c8cfdf8084 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-35796 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/ethernet/xilinx/ll_temac_main.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6d9395ba7f85bdb7af0b93272e537484ecbeff48 https://git.kernel.org/stable/c/553d294db94b5f139378022df480a9fb6c3ae39e https://git.kernel.org/stable/c/46efbdbc95a30951c2579caf97b6df2ee2b3bef3 https://git.kernel.org/stable/c/476eed5f1c22034774902a980aa48dc4662cb39a https://git.kernel.org/stable/c/7e9edb569fd9f688d887e36db8170f6e22bafbc8 https://git.kernel.org/stable/c/92c0c29f667870f17c0b764544bdf22ce0e886a1 https://git.kernel.org/stable/c/3a38a829c8bc27d78552c28e582eb1d885d07d11