In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Fix KASAN reported stack out-of-bounds read in tb_retimer_scan()
KASAN reported following issue:
BUG: KASAN: stack-out-of-bounds in tb_retimer_scan+0xffe/0x1550 [thunderbolt] Read of size 4 at addr ffff88810111fc1c by task kworker/u56:0/11 CPU: 0 UID: 0 PID: 11 Comm: kworker/u56:0 Tainted: G U 6.11.0+ #1387 Tainted: [U]=USER Workqueue: thunderbolt0 tb_handle_hotplug [thunderbolt] Call Trace: <TASK> dump_stack_lvl+0x6c/0x90 print_report+0xd1/0x630 kasan_report+0xdb/0x110 __asan_report_load4_noabort+0x14/0x20 tb_retimer_scan+0xffe/0x1550 [thunderbolt] tb_scan_port+0xa6f/0x2060 [thunderbolt] tb_handle_hotplug+0x17b1/0x3080 [thunderbolt] process_one_work+0x626/0x1100 worker_thread+0x6c8/0xfa0 kthread+0x2c8/0x3a0 ret_from_fork+0x3a/0x80 ret_from_fork_asm+0x1a/0x30
This happens because the loop variable still gets incremented by one so max becomes 3 instead of 2, and this makes the second loop read past the the array declared on the stack.
Fix this by assigning to max directly in the loop body.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-genericUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-azureUpgrade linux-image-lowlatencyUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-raspiUpgrade linux-image-generic-64kUpgrade linux-image-oem-24.04Upgrade linux-image-azure-fdeUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-virtualUpgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-realtimeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-oem-24.04bUpgrade linux-image-awsUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-6.11.0-1009-gcp | Feb 20, 2025 | Nov 9, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub