CVE-2024-39461: clk: bcm: rpi: Assign ->num before accessing ->hws
In the Linux kernel, the following vulnerability has been resolved:
clk: bcm: rpi: Assign ->num before accessing ->hws
Commit f316cdff8d67 ("clk: Annotate struct clkhwonecelldata with countedby") annotated the hws member of 'struct clkhwonecelldata' with countedby, which informs the bounds sanitizer about the number of elements in hws, so that it can warn when hws is accessed out of bounds. As noted in that change, the countedby member must be initialized with the number of elements before the first array access happens, otherwise there will be a warning from each access prior to the initialization because the number of elements is zero. This occurs in raspberrypidiscoverclocks() due to ->num being assigned after ->hws has been accessed:
UBSAN: array-index-out-of-bounds in drivers/clk/bcm/clk-raspberrypi.c:374:4 index 3 is out of range for type 'struct clkhw [] countedby(num)' (aka 'struct clkhw []')
Move the ->num initialization to before the first access of ->hws, which clears up the warning.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39461?
CVE-2024-39461 has been classified as a moderate severity vulnerability affecting the Linux kernel.
How do I fix CVE-2024-39461?
To mitigate CVE-2024-39461, update to the patched versions of the Linux kernel provided by your distribution.
What systems are affected by CVE-2024-39461?
CVE-2024-39461 affects specific versions of the Linux kernel, particularly versions between 6.6 and 6.6.34 and between 6.7 and 6.9.5.
What type of issue is CVE-2024-39461?
CVE-2024-39461 involves improper initialization in the clock subsystem of the Linux kernel that can lead to unexpected behavior.
Is CVE-2024-39461 being actively exploited?
As of the current information, there are no public reports of CVE-2024-39461 being actively exploited in the wild.