An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 6.7 | Medium | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Product | Vendor | Version |
---|---|---|
Linux kernel: i2c: xgene-slimpro | n/a | n/a |