In the Linux kernel, the following vulnerability has been resolved:
i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_smbus_xfer
The data->block[0] variable comes from user. Without proper check, the variable may be very large to cause an out-of-bounds bug.
Fix this bug by checking the value of data->block[0] first.
- commit 39244cc75482 ("i2c: ismt: Fix an out-of-bounds bug in
- commit 92fbb6d1296f ("i2c: xgene-slimpro: Fix out-of-bounds bug in