i2c: smbus: fix NULL function pointer dereference
Summary
| CVE | CVE-2024-35984 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-20 10:15:12 UTC |
| Updated | 2026-05-12 12:16:45 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: fix NULL function pointer dereference Baruch reported an OOPS when using the designware controller as target only. Target-only modes break the assumption of one transfer function always being available. Fix this by always checking the pointer in __i2c_transfer. [wsa: dropped the simplification in core-smbus to avoid theoretical regressions] |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-476
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 40f1d79f07b49c8a64a861706e5163f2db4bd95d git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 ad3c3ac7a03be3697114f781193dd3e9d97e6e23 git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 5fd72404587d7db4acb2d241fd8c387afb0a7aec git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 5a09eae9a7db597fe0c1fc91636205b4a25d2620 git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 4e75e222d397c6752b229ed72fc4644c8c36ecde git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 e3425674ff68dc521c57c6eabad0cbd20a027d85 git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 357c64ef1ef39b1e7cd91ab6bdd304d043702c83 git | Not specified |
| CNA | Linux | Linux | affected 63453b59e41173241c4efe9335815f6432fa8586 91811a31b68d3765b3065f4bb6d7d6d84a7cfc9f git | Not specified |
| CNA | Linux | Linux | affected 4.19 | Not specified |
| CNA | Linux | Linux | unaffected 4.19 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.313 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.275 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.216 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.158 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.90 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.30 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8.9 6.8.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.9 * original_commit_for_fix | Not specified |
| ADP | Siemens | RUGGEDCOM RST2428P | affected V3.1 custom | Not specified |
| ADP | Siemens | SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 Family | unaffected * custom | Not specified |
| ADP | Siemens | SCALANCE XCM-/XRM-/XCH-/XRH-300 Family | affected V3.1 custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem | affected * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/40f1d79f07b49c8a64a861706e5163f2db4bd95d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5a09eae9a7db597fe0c1fc91636205b4a25d2620 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00017.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| git.kernel.org/stable/c/357c64ef1ef39b1e7cd91ab6bdd304d043702c83 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/4e75e222d397c6752b229ed72fc4644c8c36ecde | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/e3425674ff68dc521c57c6eabad0cbd20a027d85 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-265688.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/5fd72404587d7db4acb2d241fd8c387afb0a7aec | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ad3c3ac7a03be3697114f781193dd3e9d97e6e23 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-613116.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/91811a31b68d3765b3065f4bb6d7d6d84a7cfc9f | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00020.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.