In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is called in a loop while 'operation->length' upper bound is not checked and 'data_idx' also increments.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 8.5.1.5 |
| Linux | Linux | 8.5.2.4 |
| Linux | Linux | 3.0, 3.1, 3.2, 3.3 |
| Linux | Linux | n/a |