An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc | third party advisory patch |
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c09581a52765a85f19fc35340127396d5e3379cc | patch vendor advisory |
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.12 | release notes vendor advisory |
https://usn.ubuntu.com/4115-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/4118-1/ | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20190905-0002/ | third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html | third party advisory vendor advisory |
https://usn.ubuntu.com/4147-1/ | third party advisory vendor advisory |