{"id":"DEBIAN-CVE-2024-50227","details":"In the Linux kernel, the following vulnerability has been resolved:  thunderbolt: Fix KASAN reported stack out-of-bounds read in tb_retimer_scan()  KASAN reported following issue:   BUG: KASAN: stack-out-of-bounds in tb_retimer_scan+0xffe/0x1550 [thunderbolt]  Read of size 4 at addr ffff88810111fc1c by task kworker/u56:0/11  CPU: 0 UID: 0 PID: 11 Comm: kworker/u56:0 Tainted: G     U             6.11.0+ #1387  Tainted: [U]=USER  Workqueue: thunderbolt0 tb_handle_hotplug [thunderbolt]  Call Trace:   \u003cTASK\u003e   dump_stack_lvl+0x6c/0x90   print_report+0xd1/0x630   kasan_report+0xdb/0x110   __asan_report_load4_noabort+0x14/0x20   tb_retimer_scan+0xffe/0x1550 [thunderbolt]   tb_scan_port+0xa6f/0x2060 [thunderbolt]   tb_handle_hotplug+0x17b1/0x3080 [thunderbolt]   process_one_work+0x626/0x1100   worker_thread+0x6c8/0xfa0   kthread+0x2c8/0x3a0   ret_from_fork+0x3a/0x80   ret_from_fork_asm+0x1a/0x30  This happens because the loop variable still gets incremented by one so max becomes 3 instead of 2, and this makes the second loop read past the the array declared on the stack.  Fix this by assigning to max directly in the loop body.","modified":"2026-09-15T09:02:59.107730121Z","published":"2024-11-09T11:15:08.383Z","upstream":["CVE-2024-50227"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50227"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50227.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50227.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}