Lucene search

K
redhatcveRedhat.comRH:CVE-2024-42092
HistoryJul 31, 2024 - 9:17 a.m.

CVE-2024-42092

2024-07-3109:17:57
redhat.com
access.redhat.com
6
linux kernel
cve-2024-42092
vulnerability
resolved
gpio
davinci
device tree
linux verification center

AI Score

7.1

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved: gpio: davinci: Validate the obtained number of IRQs Value of pdata->gpio_unbanked is taken from Device Tree. In case of broken DT due to any error this value can be any. Without this value validation there can be out of chips->irqs array boundaries access in davinci_gpio_probe(). Validate the obtained nirq value so that it won’t exceed the maximum number of IRQs per bank. Found by Linux Verification Center (linuxtesting.org) with SVACE.