Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-42130
HistoryJul 30, 2024 - 7:46 a.m.

CVE-2024-42130 nfc/nci: Add the inconsistency check between the input data length and count

2024-07-3007:46:26
Linux
github.com
3
linux kernel vulnerability
nfc
nci
write() call
data length
count value
nci_rf_intf_activated_ntf_packet()
comparison

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

nfc/nci: Add the inconsistency check between the input data length and count

write$nci(r0, &(0x7f0000000740)=ANY=[@ANYBLOB=“610501”], 0xf)

Syzbot constructed a write() call with a data length of 3 bytes but a count value
of 15, which passed too little data to meet the basic requirements of the function
nci_rf_intf_activated_ntf_packet().

Therefore, increasing the comparison between data length and count value to avoid
problems caused by inconsistent data length and count.

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial