From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21C221474A2 for ; Sat, 17 Aug 2024 09:23:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886607; cv=none; b=Yl3OTwXji2WuCyaWlI4a7UP9SrQeGI9FkuNAcFsSPGL9jJ2MDDLBdPrKea6dEtmnBSgsR05XUsyIAt2stw/whJNGFtLZNFMIvhQY2SD7nZAxl5V15j529/2op4Od9knrfFCVl4nAGjuqHl9bKX5b0euJjTtuqo2C8ajYiTxgod4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886607; c=relaxed/simple; bh=Mc+/HldJal/xPWNkMH83qTphwQkGeLOgCwE0cHILqpM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DSqqXiHXutxfmeoLRY8sMLquQU47aABmgesrPZ9QZEj0LpB14KTQXjwaf//hr3UFN3csPxmuzAzOwxg0DcZ2fhKbAMfQnCIMJbUFmi1byy046VuGecxXaBr+YQJcd5YL8Maa7rYLTWtZYmj5gXkyOFXABKFkGM+xBwd8ZQOPK6M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Lv9GFxHE; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Lv9GFxHE" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 96E3BC116B1; Sat, 17 Aug 2024 09:23:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1723886607; bh=Mc+/HldJal/xPWNkMH83qTphwQkGeLOgCwE0cHILqpM=; h=From:To:Cc:Subject:Date:Reply-to:From; b=Lv9GFxHE4Km9H+JvwHH6mnjpdmrfymWIoIfBLbTyj8HwnsBgC9HCY9c4pMJaEW91f AwZgQcitW8Wsum73cuiZ3tQJBhRjhPe8GoiQ+TyPrzwl24gP7Vf8HeblXBqsr4mtBx 9zT7TwiMXU4uCy8G782uZQlyMMfb2ipKjUgK1OG0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-43839: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures Date: Sat, 17 Aug 2024 11:22:43 +0200 Message-ID: <2024081729-CVE-2024-43839-ea03@gregkh> X-Mailer: git-send-email 2.46.0 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2577; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Mc+/HldJal/xPWNkMH83qTphwQkGeLOgCwE0cHILqpM=; b=owGbwMvMwCRo6H6F97bub03G02pJDGkHsq+FXJQ70ecoqr/b+PBcmaPv7uxpeB3ketjgZNxx8 /51CR0HO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAi6d8Z5ml97nPQvqeTHZC3 cm9YU+T/PwveuDEsWHbmFwNvh8bLSdWfRLuVZYu9F1Q+BgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: bna: adjust 'name' buf size of bna_tcb and bna_ccb structures To have enough space to write all possible sprintf() args. Currently 'name' size is 16, but the first '%s' specifier may already need at least 16 characters, since 'bnad->netdev->name' is used there. For '%d' specifiers, assume that they require: * 1 char for 'tx_id + tx_info->tcb[i]->id' sum, BNAD_MAX_TXQ_PER_TX is 8 * 2 chars for 'rx_id + rx_info->rx_ctrl[i].ccb->id', BNAD_MAX_RXP_PER_RX is 16 And replace sprintf with snprintf. Detected using the static analysis tool - Svace. The Linux kernel CVE team has assigned CVE-2024-43839 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.37 with commit 8b230ed8ec96 and fixed in 6.1.103 with commit ab748dd10d87 Issue introduced in 2.6.37 with commit 8b230ed8ec96 and fixed in 6.6.44 with commit b0ff0cd0847b Issue introduced in 2.6.37 with commit 8b230ed8ec96 and fixed in 6.10.3 with commit e0f48f51d55f Issue introduced in 2.6.37 with commit 8b230ed8ec96 and fixed in 6.11-rc1 with commit c9741a03dc8e Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-43839 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/ethernet/brocade/bna/bna_types.h drivers/net/ethernet/brocade/bna/bnad.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ab748dd10d8742561f2980fea08ffb4f0cacfdef https://git.kernel.org/stable/c/b0ff0cd0847b03c0a0abe20cfa900eabcfcb9e43 https://git.kernel.org/stable/c/e0f48f51d55fb187400e9787192eda09fa200ff5 https://git.kernel.org/stable/c/c9741a03dc8e491e57b95fba0058ab46b7e506da