Description

In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected, affected

CVE List62936009f35a6659cc3ebe0d90c754182d60da73 to < 4c6e64cae2b2dab32ad9099faa339f6a72c0ce16affected
62936009f35a6659cc3ebe0d90c754182d60da73 to < 8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80affected
62936009f35a6659cc3ebe0d90c754182d60da73 to < 1842d45f461a78988254631893329bdf4596e954affected
62936009f35a6659cc3ebe0d90c754182d60da73 to < 29b916d3556bd12a95be7c56ca391b8cd572f8beaffected
62936009f35a6659cc3ebe0d90c754182d60da73 to < c2130f6553f4a5cbdc259de069600117a995f197affected
2.6.36affected
Before 2.6.36unaffected
6.6.148 to ≤ 6.6.*unaffected
6.12.101 to ≤ 6.12.*unaffected
6.18.42 to ≤ 6.18.*unaffected
7.1.6 to ≤ 7.1.*unaffected
7.2-rc4 to ≤ *unaffected
OSV2.6.36 to < 6.6.148 · Fixed in 6.6.148affected
6.7.0 to < 6.12.101 · Fixed in 6.12.101affected
6.13.0 to < 6.18.42 · Fixed in 6.18.42affected
6.19.0 to < 7.1.6 · Fixed in 7.1.6affected

References

8