Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
Sashiko (locally) reports multiple out-of-bound issues in ffa_setup_and_transmit:
-
Writing ep_mem_access->reserved can write out of bounds for FFA versions < 1.2 as ffa_emad_size_get() returns 16 bytes in that case while reserved has an offset of 24. Instead of zeroing fields, memset the struct to zero first based on the FFA version.
-
Make sure there is enough size to write constituents.
While at it, convert the only sizeof() in the driver that uses a type instead of variable.
Details
- Affected product:
- Debian 10 ELS
- Affected packages:
- linux @ 4.19.0