In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix copy buffer page size For non-registered buffer, fastrpc driver copies the buffer and pass it to the remote subsystem. There is a problem with current implementation of page size calculation which is not considering the offset in the calculation. This might lead to passing of improper and out-of-bounds page size which could result in memory issue. Calculate page start and page end using the offset adjusted address instead of absolute address.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 7.1.1 |
| Linux | Linux | < c977426db644ba476938125597947979e8aba725 |