Description
In the Linux kernel, the following vulnerability has been resolved: iommu: Fix two issues in iommu_copy_struct_from_user() In the review for iommu_copy_struct_to_user() helper, Matt pointed out that a NULL pointer should be rejected prior to dereferencing it: https://lore.kernel.org/all/86881827-8E2D-461C-BDA3-FA8FD14C343C@nvidia.com And Alok pointed out a typo at the same time: https://lore.kernel.org/all/480536af-6830-43ce-a327-adbd13dc3f1d@oracle.com Since both issues were copied from iommu_copy_struct_from_user(), fix them first in the current header.
Product status
e9d36c07bb787840e4813fb09a929a17d522a69f (git) before 2e303d010722787dc84d94f68d70fe10dfc1b9ea
e9d36c07bb787840e4813fb09a929a17d522a69f (git) before 967d6f0d9a20a1bf15ee7ed881e2d4e532e22709
e9d36c07bb787840e4813fb09a929a17d522a69f (git) before 30a3f2f3e4bd6335b727c83c08a982d969752bc1
6.7
Any version before 6.7
6.12.28 (semver)
6.14.6 (semver)
6.15 (original_commit_for_fix)
References
git.kernel.org/...c/2e303d010722787dc84d94f68d70fe10dfc1b9ea
git.kernel.org/...c/967d6f0d9a20a1bf15ee7ed881e2d4e532e22709
git.kernel.org/...c/30a3f2f3e4bd6335b727c83c08a982d969752bc1