In the Linux kernel, the following vulnerability has been resolved:
i2c: validate user data in compat ioctl
Wrong user data may cause warning in i2c_transfer(), ex: zero msgs. Userspace should not be able to trigger warnings, so this patch adds validation checks for user data in compact ioctl to prevent reported warnings
[
{
"events": [
{
"introduced": "4.15.0"
},
{
"fixed": "4.19.224"
}
]
},
{
"events": [
{
"introduced": "4.20.0"
},
{
"fixed": "5.4.170"
}
]
},
{
"events": [
{
"introduced": "5.5.0"
},
{
"fixed": "5.10.90"
}
]
},
{
"events": [
{
"introduced": "5.11.0"
},
{
"fixed": "5.15.13"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-46934.json"