Summary: | [Security] Array index error in sys/dev/iir/iir.c | ||
---|---|---|---|
Product: | Base System | Reporter: | ChenHao Lu <thresh416> |
Component: | kern | Assignee: | Ed Maste <emaste> |
Status: | Closed FIXED | ||
Severity: | Affects Many People | CC: | emaste |
Priority: | --- | ||
Version: | 13.2-STABLE | ||
Hardware: | Any | ||
OS: | Any |
Description
ChenHao Lu
2023-08-24 12:46:05 UTC
A commit in branch stable/13 references this bug: URL: https://cgit.FreeBSD.org/src/commit/?id=b5a5a06fc012d27c6937776bff8469ea465c3873 commit b5a5a06fc012d27c6937776bff8469ea465c3873 Author: Ed Maste <emaste@FreeBSD.org> AuthorDate: 2023-08-28 03:38:30 +0000 Commit: Ed Maste <emaste@FreeBSD.org> CommitDate: 2023-08-28 19:37:09 +0000 iir: prevent negative offsets in ioctl Direct commit to stable/13 as this driver has been removed from main in commit 399188a2c60c ("iir: Remove"). PR: 273328 Reported by: ChenHao Lu Sponsored by: The FreeBSD Foundation sys/dev/iir/iir.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) Should we apply for a CVE for this security problem? *** Bug 273173 has been marked as a duplicate of this bug. *** A commit in branch stable/12 references this bug: URL: https://cgit.FreeBSD.org/src/commit/?id=e4e41b39a4dc22a31c7d239ca1ac29bdd6c10b47 commit e4e41b39a4dc22a31c7d239ca1ac29bdd6c10b47 Author: Ed Maste <emaste@FreeBSD.org> AuthorDate: 2023-08-28 03:38:30 +0000 Commit: Ed Maste <emaste@FreeBSD.org> CommitDate: 2023-09-09 15:16:19 +0000 iir: prevent negative offsets in ioctl MFS of direct commit to stable/13 as this driver has been removed from main in commit 399188a2c60c ("iir: Remove"). PR: 273328 Reported by: ChenHao Lu Sponsored by: The FreeBSD Foundation (cherry picked from commit b5a5a06fc012d27c6937776bff8469ea465c3873) sys/dev/iir/iir.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) Applied to stable/13 and stable/12, thanks for the report. |