In the Linux kernel, the following vulnerability has been resolved:
platform/x86: toshiba_acpi: Fix array out-of-bounds access
In order to use toshibadmiquirks[] together with the standard DMI matching functions, it must be terminated by a empty entry.
Since this entry is missing, an array out-of-bounds access occurs every time the quirk list is processed.
Fix this by adding the terminating empty entry.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0d71da43d6b7916d36cf1953d793da80433c50bf",
"id": "CVE-2024-41028-25993d44",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/toshiba_acpi.c"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"245713058827384736066903546693420025853",
"222622807998441831199677115871667278071",
"34241411368976995045939358967897505362",
"154097356534219478532282718402292467528"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@639868f1cb87b683cf830353bbee0c4078202313",
"id": "CVE-2024-41028-4c06a7a8",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/toshiba_acpi.c"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"245713058827384736066903546693420025853",
"222622807998441831199677115871667278071",
"34241411368976995045939358967897505362",
"154097356534219478532282718402292467528"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b6e02c6b0377d4339986e07aeb696c632cd392aa",
"id": "CVE-2024-41028-7cc8af9d",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/toshiba_acpi.c"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"245713058827384736066903546693420025853",
"222622807998441831199677115871667278071",
"34241411368976995045939358967897505362",
"154097356534219478532282718402292467528"
]
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e030aa6c972641cb069086a8c7a0f747653e472a",
"id": "CVE-2024-41028-e58c1699",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/toshiba_acpi.c"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"245713058827384736066903546693420025853",
"222622807998441831199677115871667278071",
"34241411368976995045939358967897505362",
"154097356534219478532282718402292467528"
]
}
}
]