Description
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer is written Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated before the buffer is written, potentially causing race conditions where the host sees an updated read pointer before the buffer is actually written. Updating rd_offset prematurely can lead to the host accessing an uninitialized or incomplete element, resulting in data corruption. Invoke the buffer write before updating rd_offset to ensure the element is fully written before signaling its availability.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Linux / Linuxbbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 – 44b9620e82bbec2b9a6ac77f63913636d84f96dc
- Linux / Linuxbbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 – f704a80d9fa268e51a6cc5242714502c3c1fa605
- Linux / Linuxbbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 – 0007ef098dab48f1ba58364c40b4809f1e21b130
- Linux / Linuxbbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 – 6f18d174b73d0ceeaa341f46c0986436b3aefc9a
- Linux / Linux5.19 – 5.19
- Linux / Linux0 – 5.19
- Linux / Linux6.6.95 – 6.6.*
- Linux / Linux6.12.35 – 6.12.*
- Linux / Linux6.15.4 – 6.15.*
- Linux / Linux6.16 – *
- Linux / Linux kernel5.19 – 6.6.95
References
- MISChttps://git.kernel.org/stable/c/44b9620e82bbec2b9a6ac77f63913636d84f96dc
- MISChttps://git.kernel.org/stable/c/f704a80d9fa268e51a6cc5242714502c3c1fa605
- MISChttps://git.kernel.org/stable/c/0007ef098dab48f1ba58364c40b4809f1e21b130
- MISChttps://git.kernel.org/stable/c/6f18d174b73d0ceeaa341f46c0986436b3aefc9a
Updated 22m ago · 8 sources