В ядре Linux устранена следующая уязвимость:
cxl/ras: исправлено чтение регистра AER cxl_rch_get_aer_info() за пределами границ.
cxl_rch_get_aer_info() копирует возможность AER нисходящего порта RCH из
блок RCRB MMIO с использованием цикла readl(), ограниченного sizeof(struct
aer_capability_regs). Эта структура представляет собой макет программного обеспечения и встроенную в него структуру.
struct pcie_tlp_log больше, чем возможности проводного AER. Как
В результате цикл считывает сопоставленный блок регистров AER.
Перечтение также заполняет хвостовые поля, предназначенные только для программного обеспечения, включая
header_log.header_len. Header_len, выходящий за пределы допустимого диапазона, передан
pcie_print_tlp_log() может затем пройти мимо буфера журнала заголовков и вызвать
второе чтение за пределами поля. Чтение было правильным, когда оно было введено, но с тех пор структура pcie_tlp_log изменилась.
выросли (размеры журнала заголовков и префиксов TLP, поля header_len и flit),
поэтому sizeof(struct aer_capability_regs) больше не соответствует физическому AER
возможности.
Привязка чтения к физическим регистрам AER, заголовок через 16 байт. Заголовок журнала. Сначала обнулите пункт назначения, чтобы поля, предназначенные только для программного обеспечения, были детерминированный.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from the RCRB MMIO block using a readl() loop bounded by sizeof(struct aer_capability_regs). This struct is a software layout and its embedded struct pcie_tlp_log is larger than the on-wire AER capability. As a result the loop reads past the mapped AER register block. The over-read also populates the software-only tail fields including header_log.header_len. An out-of-range header_len passed to pcie_print_tlp_log() can then loop past the header log buffer and cause a second out-of-bounds read. The read was correct when introduced, but struct pcie_tlp_log has since grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), so sizeof(struct aer_capability_regs) no longer matches the physical AER capability. Bound the read to the physical AER registers, header through the 16 byte Header Log. Zero the destination first so the software-only fields are deterministic.
Характеристики атаки
Последствия
Строка CVSS v3.1
Уязвимые продукты 3
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
6.7
|
6.18.51
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
6.7
|
7.2.4
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
6.7
|
7.3-rc1
|