{"id":"DEBIAN-CVE-2024-46743","details":"In the Linux kernel, the following vulnerability has been resolved:  of/irq: Prevent device address out-of-bounds read in interrupt map walk  When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells property), KASAN detects the following out-of-bounds read when populating the initial match table (dyndbg=\"func of_irq_parse_* +p\"):    OF: of_irq_parse_one: dev=/soc@0/picasso/watchdog, index=0   OF:  parent=/soc@0/pci@878000000000/gpio0@17,0, intsize=2   OF:  intspec=4   OF: of_irq_parse_raw: ipar=/soc@0/pci@878000000000/gpio0@17,0, size=2   OF:  -\u003e addrsize=3   ==================================================================   BUG: KASAN: slab-out-of-bounds in of_irq_parse_raw+0x2b8/0x8d0   Read of size 4 at addr ffffff81beca5608 by task bash/764    CPU: 1 PID: 764 Comm: bash Tainted: G           O       6.1.67-484c613561-nokia_sm_arm64 #1   Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.01-12.24.03-dirty 01/01/2023   Call trace:    dump_backtrace+0xdc/0x130    show_stack+0x1c/0x30    dump_stack_lvl+0x6c/0x84    print_report+0x150/0x448    kasan_report+0x98/0x140    __asan_load4+0x78/0xa0    of_irq_parse_raw+0x2b8/0x8d0    of_irq_parse_one+0x24c/0x270    parse_interrupts+0xc0/0x120    of_fwnode_add_links+0x100/0x2d0    fw_devlink_parse_fwtree+0x64/0xc0    device_add+0xb38/0xc30    of_device_add+0x64/0x90    of_platform_device_create_pdata+0xd0/0x170    of_platform_bus_create+0x244/0x600    of_platform_notify+0x1b0/0x254    blocking_notifier_call_chain+0x9c/0xd0    __of_changeset_entry_notify+0x1b8/0x230    __of_changeset_apply_notify+0x54/0xe4    of_overlay_fdt_apply+0xc04/0xd94    ...    The buggy address belongs to the object at ffffff81beca5600    which belongs to the cache kmalloc-128 of size 128   The buggy address is located 8 bytes inside of    128-byte region [ffffff81beca5600, ffffff81beca5680)    The buggy address belongs to the physical page:   page:00000000230d3d03 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1beca4   head:00000000230d3d03 order:1 compound_mapcount:0 compound_pincount:0   flags: 0x8000000000010200(slab|head|zone=2)   raw: 8000000000010200 0000000000000000 dead000000000122 ffffff810000c300   raw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000   page dumped because: kasan: bad access detected    Memory state around the buggy address:    ffffff81beca5500: 04 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc    ffffff81beca5580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc   \u003effffff81beca5600: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc                         ^    ffffff81beca5680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc    ffffff81beca5700: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc   ==================================================================   OF:  -\u003e got it !  Prevent the out-of-bounds read by copying the device address into a buffer of sufficient size.","modified":"2026-09-15T09:03:11.705046507Z","published":"2024-09-18T08:15:03.540Z","upstream":["CVE-2024-46743"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-46743"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.112-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46743.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46743.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46743.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}