In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ handler") introduces a range check for if_id to avoid an out-of-bounds access. If an out-of-bounds if_id is detected, the interrupt status is not cleared. This may result in an interrupt storm. Clear the interrupt status after detecting an out-of-bounds if_id to avoid the problem. Found by an experimental AI code review agent at Google.
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: dpaa2-switch: Corrección de tormenta de interrupciones después de recibir un if_id incorrecto en el gestor IRQ El commit 31a7a0bbeb00 ('dpaa2-switch: añade comprobación de límites para if_id en el gestor IRQ') introduce una comprobación de rango para if_id para evitar un acceso fuera de límites. Si se detecta un if_id fuera de límites, el estado de la interrupción no se borra. Esto puede resultar en una tormenta de interrupciones. Borrar el estado de la interrupción después de detectar un if_id fuera de límites para evitar el problema. Encontrado por un agente experimental de revisión de código de IA en Google.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a597b500> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24246e49c0> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5978f00> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d24246e5a40> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a597b400> | Operating System |
| linux | linux_kernel | * | <built-in method update of dict object at 0x7d23a5978f80> | Operating System |
| linux | linux_kernel | 6.19 | <built-in method update of dict object at 0x7d23a597bcc0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a59793c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24246e67c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a597b440> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24661ef800> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d24246e6a80> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d23a597a4c0> | Operating System |
| linux | linux_kernel | 7.0 | <built-in method update of dict object at 0x7d2450e5b8c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:6.19:-:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |
| Yes | cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* |