In the Linux kernel, the following vulnerability has been resolved: i3c: master: mipi-i3c-hci: Fix a kernel panic for accessing DAT_data. The i3c_master_bus_init
function may attach the I2C devices before the I3C bus initialization. In this flow, the DAT alloc_entry`` will be used before the DAT
init. Additionally, if the
i3c_master_bus_initfails, the DAT
cleanupwill execute before the device is detached, which will execue DAT
free_entry` function. The above scenario can cause the driver to use DAT_data when it is NULL.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | linux | < 6.1.64-1 | linux_6.1.64-1_all.deb |
Debian | 11 | all | linux | <= 5.10.223-1 | linux_5.10.223-1_all.deb |
Debian | 999 | all | linux | < 6.6.8-1 | linux_6.6.8-1_all.deb |
Debian | 13 | all | linux | < 6.6.8-1 | linux_6.6.8-1_all.deb |