Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in atomfirmware.h, but firmware provides a bigger one sometimes. Deferencing the larger array causes an out of bounds error. commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error in bios parser") fixed some of this, but there are two other cases not covered by it. Fix those as well.
Product status
ae79c310b1a6f97429a5784b65f125d9cc9c95b1 (git) before b8e7589f50b709b647b642531599e70707faf70c
ae79c310b1a6f97429a5784b65f125d9cc9c95b1 (git) before 66acfe798cd08b36cfbb65a30fab3159811304a7
ae79c310b1a6f97429a5784b65f125d9cc9c95b1 (git) before 5675ecd2e0b00a4318ba1db1a1234e7d45b13d6b
ae79c310b1a6f97429a5784b65f125d9cc9c95b1 (git) before dea2dbec716c38a0b73b6ad01d91e2b120cc5f1e
ae79c310b1a6f97429a5784b65f125d9cc9c95b1 (git) before d116db180decec1b21bba31d2ff495ac4d8e1b83
4.15
Any version before 4.15
5.10.181 (semver)
5.15.113 (semver)
6.1.30 (semver)
6.3.4 (semver)
6.4 (original_commit_for_fix)
References
git.kernel.org/...c/b8e7589f50b709b647b642531599e70707faf70c
git.kernel.org/...c/66acfe798cd08b36cfbb65a30fab3159811304a7
git.kernel.org/...c/5675ecd2e0b00a4318ba1db1a1234e7d45b13d6b
git.kernel.org/...c/dea2dbec716c38a0b73b6ad01d91e2b120cc5f1e
git.kernel.org/...c/d116db180decec1b21bba31d2ff495ac4d8e1b83