CVE-2021-28952

Related Vulnerabilities: CVE-2021-28952  

An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)

Additional Information

  • Bugzilla 1941774: CVE-2021-28952 kernel: buffer overflow in sound/soc/qcom/sdm845.c when an unexpected port ID number is encountered
  • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  • FAQ: Frequently asked questions about CVE-2021-28952