CVE-2024-43825: iio: Fix the sorting functionality in iio_gts_build_avail_time_table
In the Linux kernel, the following vulnerability has been resolved:
iio: Fix the sorting functionality in iiogtsbuildavailtimetable
The sorting in iiogtsbuildavailtimetable is not working as intended. It could result in an out-of-bounds access when the time is zero.
Here are more details:
1. When the gts->itimetable[i].timeus is zero, e.g., the time sequence is 3, 0, 1, the inner for-loop will not terminate and do out-of-bound writes. This is because once times[j] > new, the value new will be added in the current position and the times[j] will be moved to j+1 position, which makes the if-condition always hold. Meanwhile, idx will be added one, making the loop keep running without termination and out-of-bound write. 2. If none of the gts->itimetable[i].timeus is zero, the elements will just be copied without being sorted as described in the comment "Sort times from all tables to one and remove duplicates".
For more details, please refer to https://lore.kernel.org/all/6dd0d822-046c-4dd2-9532-79d7ab96ec05@gmail.com.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43825?
CVE-2024-43825 has a medium severity rating due to the potential for out-of-bounds access.
How do I fix CVE-2024-43825?
To fix CVE-2024-43825, update the Linux Kernel to a version that includes the patch for this vulnerability.
Which versions of the Linux Kernel are affected by CVE-2024-43825?
CVE-2024-43825 affects Linux Kernel versions from 6.4 to 6.6.44 and from 6.7 to 6.10.3.
What issues can arise from CVE-2024-43825?
CVE-2024-43825 may cause out-of-bounds access issues that could lead to system instability.
Is there a known exploit for CVE-2024-43825?
As of now, there are no public reports of exploits actively targeting CVE-2024-43825.