2024-11-19 18:00:48 +00:00
{
2024-12-24 12:01:02 +00:00
"data_version" : "4.0" ,
2024-11-19 18:00:48 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2024-53156" ,
2024-12-24 12:01:02 +00:00
"ASSIGNER" : "cve@kernel.org" ,
"STATE" : "PUBLIC"
2024-11-19 18:00:48 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2024-12-24 12:01:02 +00:00
"value" : "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()\n\nI found the following bug in my fuzzer:\n\n UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath9k/htc_hst.c:26:51\n index 255 is out of range for type 'htc_endpoint [22]'\n CPU: 0 UID: 0 PID: 8 Comm: kworker/0:0 Not tainted 6.11.0-rc6-dirty #14\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Workqueue: events request_firmware_work_func\n Call Trace:\n <TASK>\n dump_stack_lvl+0x180/0x1b0\n __ubsan_handle_out_of_bounds+0xd4/0x130\n htc_issue_send.constprop.0+0x20c/0x230\n ? _raw_spin_unlock_irqrestore+0x3c/0x70\n ath9k_wmi_cmd+0x41d/0x610\n ? mark_held_locks+0x9f/0xe0\n ...\n\nSince this bug has been confirmed to be caused by insufficient verification\nof conn_rsp_epid, I think it would be appropriate to add a range check for\nconn_rsp_epid to htc_connect_service() to prevent the bug from occurring."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Linux" ,
"product" : {
"product_data" : [
{
"product_name" : "Linux" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "fb9987d0f748c983bb795a86f47522313f701a08" ,
"version_value" : "5f177fb9d01355ac183e65ad8909ea8ef734e0cf"
} ,
{
"version_value" : "not down converted" ,
"x_cve_json_5_version_data" : {
"versions" : [
{
"version" : "2.6.35" ,
"status" : "affected"
} ,
{
"version" : "0" ,
"lessThan" : "2.6.35" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "4.19.325" ,
"lessThanOrEqual" : "4.19.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "5.4.287" ,
"lessThanOrEqual" : "5.4.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "5.10.231" ,
"lessThanOrEqual" : "5.10.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "5.15.174" ,
"lessThanOrEqual" : "5.15.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "6.1.120" ,
"lessThanOrEqual" : "6.1.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "6.6.64" ,
"lessThanOrEqual" : "6.6.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "6.11.11" ,
"lessThanOrEqual" : "6.11.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "6.12.2" ,
"lessThanOrEqual" : "6.12.*" ,
"status" : "unaffected" ,
"versionType" : "semver"
} ,
{
"version" : "6.13-rc1" ,
"lessThanOrEqual" : "*" ,
"status" : "unaffected" ,
"versionType" : "original_commit_for_fix"
}
] ,
"defaultStatus" : "affected"
}
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://git.kernel.org/stable/c/5f177fb9d01355ac183e65ad8909ea8ef734e0cf" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/5f177fb9d01355ac183e65ad8909ea8ef734e0cf"
} ,
{
"url" : "https://git.kernel.org/stable/c/cb480ae80fd4d0f1ac9e107ce799183beee5124b" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/cb480ae80fd4d0f1ac9e107ce799183beee5124b"
} ,
{
"url" : "https://git.kernel.org/stable/c/c941af142200d975dd3be632aeb490f4cb91dae4" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/c941af142200d975dd3be632aeb490f4cb91dae4"
} ,
{
"url" : "https://git.kernel.org/stable/c/8965db7fe2e913ee0802b05fc94c6d6aa74e0596" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/8965db7fe2e913ee0802b05fc94c6d6aa74e0596"
} ,
{
"url" : "https://git.kernel.org/stable/c/70eae50d2156cb6e078d0d78809b49bf2f4c7540" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/70eae50d2156cb6e078d0d78809b49bf2f4c7540"
} ,
{
"url" : "https://git.kernel.org/stable/c/b6551479daf2bfa80bfd5d9016b02a810e508bfb" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/b6551479daf2bfa80bfd5d9016b02a810e508bfb"
} ,
{
"url" : "https://git.kernel.org/stable/c/3fe99b9690b99606d3743c9961ebee865cfa1ab8" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/3fe99b9690b99606d3743c9961ebee865cfa1ab8"
} ,
{
"url" : "https://git.kernel.org/stable/c/bc981179ab5d1a2715f35e3db4e4bb822bacc849" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/bc981179ab5d1a2715f35e3db4e4bb822bacc849"
} ,
{
"url" : "https://git.kernel.org/stable/c/8619593634cbdf5abf43f5714df49b04e4ef09ab" ,
"refsource" : "MISC" ,
"name" : "https://git.kernel.org/stable/c/8619593634cbdf5abf43f5714df49b04e4ef09ab"
2024-11-19 18:00:48 +00:00
}
]
2024-12-24 12:01:02 +00:00
} ,
"generator" : {
"engine" : "bippy-5f407fcff5a0"
2024-11-19 18:00:48 +00:00
}
}