-

CVE-2026-63892

thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow

On the non-root path, __tb_property_parse_dir() takes dir_len from
entry->length (u16 widened to size_t).  Two distinct OOB conditions
follow when entry->length < 4:

1. The non-root path begins with kmemdup(&block[dir_offset],
   sizeof(*dir->uuid), ...) which always reads 4 dwords from
   dir_offset.  tb_property_entry_valid() only enforces
   dir_offset + entry->length <= block_len, so a crafted entry
   with dir_offset close to the end of the property block and
   entry->length in 0..3 passes that gate but lets the UUID copy
   run off the block (e.g. dir_offset = 497, dir_len = 3 in a
   500-dword block reads block[497..501]).

2. After the kmemdup, content_len = dir_len - 4 underflows size_t
   to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry
   walk runs OOB on each iteration until an entry fails
   validation or the kernel oopses on an unmapped page.

Reject dir_len < 4 on the non-root path *before* the UUID kmemdup,
which closes both holes.

Also move INIT_LIST_HEAD(&dir->properties) up to immediately after
the dir allocation so the new error-return path (and the existing
uuid-alloc failure path) calling tb_property_free_dir() sees a
walkable list rather than the zero-initialized NULL next/prev that
list_for_each_entry_safe() would oops on.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < 37abc4504fa19d8f9f1e87792e8a2b8fdb308e40
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < e2d4d51cf5785815fa4e91e0c019e3eb2506a84c
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < de618299190b418291609e6921557253bd417e25
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < 5506c825f14d810f0690b1f4367cb7249ebb387a
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < 542a13890b742099c461d70920e97b14e568f6ec
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < d548179adcc87e1bc66b17e00352a1f536e76065
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < 3bec49ca55e08fb085cc4318f24b1b37eaab28cb
Status affected
Version cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Version < de21b59c29e31c5108ddc04210631bbfab81b997
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.15
Status affected
Version 0
Version < 4.15
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.125
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40
https://git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c
https://git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25
https://git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a
https://git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec
https://git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065
https://git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb
https://git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997