7.1

CVE-2023-53059

platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl

In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl

It is possible to peep kernel page's data by providing larger `insize`
in struct cros_ec_command[1] when invoking EC host commands.

Fix it by using zeroed memory.

[1]: https://elixir.bootlin.com/linux/v6.2/source/include/linux/platform_data/cros_ec_proto.h#L74
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.240
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.177
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.105
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.22
Linux ≫ Linux Kernel Version >= 6.2 < 6.2.9
Linux ≫ Linux Kernel Version 6.3 Update rc1
Linux ≫ Linux Kernel Version 6.3 Update rc2
Linux ≫ Linux Kernel Version 6.3 Update rc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.094
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/13493ad6a220cb3f6f3552a16b4f2753a118b633
Patch
https://git.kernel.org/stable/c/f86ff88a1548ccf5a13960c0e7625ca787ea0993
Patch
https://git.kernel.org/stable/c/ebea2e16504f40d2c2bac42ad5c5a3de5ce034b4
Patch
https://git.kernel.org/stable/c/eab28bfafcd1245a3510df9aa9eb940589956ea6
Patch
https://git.kernel.org/stable/c/a0d8644784f73fa39f57f72f374eefaba2bf48a0
Patch
https://git.kernel.org/stable/c/b20cf3f89c56b5f6a38b7f76a8128bf9f291bbd3
Patch