From: Greg KH <gregkh@linuxfoundation.org>
To: Giovanni Gherdovich <giovanni.gherdovich@suse.com>
Cc: cve@kernel.org, linux-kernel@vger.kernel.org,
linux-cve-announce@vger.kernel.org
Subject: Re: CVE-2025-37832: cpufreq: sun50i: prevent out-of-bounds access
Date: Fri, 30 May 2025 16:15:50 +0200 [thread overview]
Message-ID: <2025053010-legible-destiny-23d3@gregkh> (raw)
In-Reply-To: <2025053006-multitask-profanity-3590@gregkh>
On Fri, May 30, 2025 at 04:14:51PM +0200, Greg KH wrote:
> On Fri, May 30, 2025 at 03:57:35PM +0200, Giovanni Gherdovich wrote:
> > On Thu May 8, 2025 08:39, Greg Kroah-Hartman wrote:
> > > A KASAN enabled kernel reports an out-of-bounds access when handling the
> > > nvmem cell in the sun50i cpufreq driver:
> > > [...]
> >
> > The invalid data that may be read comes from a ROM in the SoC,
> > programmed by the vendor, and is only used to configure CPU frequency
> > and voltage in the cpufreq framework.
> >
> > Even assuming that improper frequency/voltage settings constitute a
> > security risk, writing to the ROM in question is at least a privileged
> > operation, and may require physical access to the SoC.
>
> Obviously there are systems out there that have this issue, with device
> trees that can trigger this issue, this isn't a matter of "malicious ROM
> doing bad things" type of issue, it's a "the DT can't express this
> properly, so we might have taken data from the hardware and handled it
> in the wrong way" type of issue.
>
> > I don't think this qualifies as vulnerability.
>
> I don't see how this is a ROM configuration issue, but rather just a
> kernel bug in how the hardware is accessed on different types of systems
> where we previously could not handle such accesses correctly.
Note, if the maintainer or the developer of the change in question here
disagrees with me, great, we'll be glad to revoke this CVE, as we defer
to them. But for some reason you didn't include them in this thread :(
thanks,
greg k-h
next prev parent reply other threads:[~2025-05-30 14:15 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <2025050824-CVE-2025-37832-e235@gregkh>
2025-05-30 13:57 ` Giovanni Gherdovich
2025-05-30 14:14 ` Greg KH
2025-05-30 14:15 ` Greg KH [this message]
2025-05-30 18:00 ` Giovanni Gherdovich
2025-06-02 12:51 ` Andre Przywara
2025-06-02 16:28 ` Giovanni Gherdovich
2025-06-04 7:44 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2025053010-legible-destiny-23d3@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=giovanni.gherdovich@suse.com \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®