CVE-2024-46676: nfc: pn533: Add poll mod list filling check
In the Linux kernel, the following vulnerability has been resolved:
nfc: pn533: Add poll mod list filling check
In case of improtocols value is 1 and tmprotocols value is 0 this combination successfully passes the check 'if (!improtocols && !tmprotocols)' in the nfcstartpoll(). But then after pn533pollcreatemodlist() call in pn533startpoll() poll mod list will remain empty and dev->pollmodcount will remain 0 which lead to division by zero.
Normally no im protocol has value 1 in the mask, so this combination is not expected by driver. But these protocol values actually come from userspace via Netlink interface (NFCCMDSTARTPOLL operation). So a broken or malicious program may pass a message containing a "bad" combination of protocol parameter values so that dev->pollmodcount is not incremented inside pn533pollcreatemodlist(), thus leading to division by zero. Call trace looks like: nfcgenlstartpoll() nfcstartpoll() ->startpoll() pn533startpoll()
Add poll mod list filling check.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46676?
CVE-2024-46676 has been classified as a moderate severity vulnerability.
How do I fix CVE-2024-46676?
To fix CVE-2024-46676, update the Linux kernel to versions 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which Linux kernel versions are affected by CVE-2024-46676?
Linux kernel versions from 3.12 up to 5.10.223-1 are affected by CVE-2024-46676.
What is the primary issue caused by CVE-2024-46676?
CVE-2024-46676 allows an incorrect validation in NFC protocols, potentially leading to improper handling of start polling.
Where can I find more information about CVE-2024-46676?
Further details regarding CVE-2024-46676 can typically be found in the Linux kernel changelogs or security advisories.