CVE-2024-35992

CVSS v3.1 5.5 (Medium)
55% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 7
NVD Status Analyzed

In the Linux kernel, the following vulnerability has been resolved:

phy: marvell: a3700-comphy: Fix out of bounds read

There is an out of bounds read access of 'gbe_phy_init_fix[fix_idx].addr'
every iteration after 'fix_idx' reaches 'ARRAY_SIZE(gbe_phy_init_fix)'.

Make sure 'gbe_phy_init[addr]' is used when all elements of
'gbe_phy_init_fix' array are handled.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Weaknesses
CWE-125
Out-of-bounds Read
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
kernel.org
Published Date
2024-05-20 10:15:13
(3 months ago)
Updated Date
2024-05-23 20:33:31
(3 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 5.18 version and prior 6.1.90 version cpe:2.3:o:linux:linux_kernel >= 5.18 < 6.1.90
  Linux Kernel from 6.2 version and prior 6.6.30 version cpe:2.3:o:linux:linux_kernel >= 6.2 < 6.6.30
  Linux Kernel from 6.7 version and prior 6.8.9 version cpe:2.3:o:linux:linux_kernel >= 6.7 < 6.8.9
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...