CVE-2023-52829: wifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps()

0.0 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps()

reg_cap.phy_id is extracted from WMI event and could be an unexpected value
in case some errors happen. As a result out-of-bound write may occur to
soc->hal_reg_cap. Fix it by validating reg_cap.phy_id before using it.

This is found during code review.

Compile tested only.

Classification

CVE ID: CVE-2023-52829

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/dfe13eaab043130f90dd3d57c7d88577c04adc97
https://git.kernel.org/stable/c/4dd0547e8b45faf6f95373be5436b66cde326c0e
https://git.kernel.org/stable/c/b302dce3d9edea5b93d1902a541684a967f3c63c

Timeline