SB2024050846 - Improper error handling in Linux kernel i2c driver
Published: May 8, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2021-46934)
The vulnerability allows a local user to produce warnings from the userspace.
The vulnerability exists due to improper error handling within the compat_i2cdev_ioctl() function in drivers/i2c/i2c-dev.c. A local user can pass specially crafted data to the driver and influence its behavior.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/407c8708fb1bf2d4afc5337ef50635cf540c364b
- https://git.kernel.org/stable/c/9e4a3f47eff476097e0c7faac04d1831fc70237d
- https://git.kernel.org/stable/c/8d31cbab4c295d7010ebb729e9d02d0e9cece18f
- https://git.kernel.org/stable/c/f68599581067e8a5a8901ba9eb270b4519690e26
- https://git.kernel.org/stable/c/bb436283e25aaf1533ce061605d23a9564447bdf