SB20241230305 - Input validation error in Linux kernel ufs core driver
Published: December 30, 2024 Updated: May 11, 2025
Security Bulletin ID
SB20241230305
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2024-56622)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the read_req_latency_avg_show() and write_req_latency_avg_show() functions in drivers/ufs/core/ufs-sysfs.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0069928727c2e95ca26c738fbe6e4b241aeaaf08
- https://git.kernel.org/stable/c/7b21233e5f72d10f08310689f993c1dbdfde9f2c
- https://git.kernel.org/stable/c/87bf3ea841a5d77beae6bb85af36b2b3848407ee
- https://git.kernel.org/stable/c/9c191055c7abea4912fdb83cb9b261732b25a0c8
- https://git.kernel.org/stable/c/eb48e9fc0028bed94a40a9352d065909f19e333c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.174
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.120
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.66