CVE-2021-47172
MEDIUMLinux Kernel - Buffer Overflow in AD7124 ADC Channel Number Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available storage. Note this bug was introduced as part of a fix to ensure we didn't rely on the ordering of child nodes. So we need to support arbitrary ordering but they all need to be there somewhere. Note I hit this when using qemu to test the rest of this series. Arguably this isn't the best fix, but it is probably the most minimal option for backporting etc. Alexandru's sign-off is here because he carried this patch in a larger set that Jonathan then applied.
References (4)
Core 4
Core References
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
13.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Products (13)
Linux/Linux
< 5.5
Linux/Linux
5.10.42 - 5.10.*
Linux/Linux
5.12.9 - 5.12.*
Linux/Linux
5.13
Linux/Linux
5.4.124 - 5.4.*
Linux/Linux
5.4.14 - 5.4.124
Linux/Linux
5.5
Linux/Linux
5408cbc6337300d6f1a87c797273c535ed96305a - f49149964d2423fb618fb6b755bb1eaa431cca2c
Linux/Linux
d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 - 26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc
Linux/Linux
d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 - f2a772c51206b0c3f262e4f6a3812c89a650191b
... and 3 more
Published
Mar 25, 2024
Tracked Since
Feb 18, 2026