CVE-2021-47642
26.02.2025, 06:37
In the Linux kernel, the following vulnerability has been resolved: video: fbdev: nvidiafb: Use strscpy() to prevent buffer overflow Coverity complains of a possible buffer overflow. However, given the 'static' scope of nvidia_setup_i2c_bus() it looks like that can't happen after examiniing the call sites. CID 19036 (#1 of 1): Copy into fixed size buffer (STRING_OVERFLOW) 1. fixed_size_dest: You might overrun the 48-character fixed-size string chan->adapter.name by copying name without checking the length. 2. parameter_as_source: Note: This defect has an elevated risk because the source argument is a parameter of the current function. 89 strcpy(chan->adapter.name, name); Fix this warning by using strscpy() which will silence the warning and prevent any future buffer overflows should the names used to identify the channel become much longer.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 4.9.311 |
linux | linux_kernel | 4.10 ≤ 𝑥 < 4.14.276 |
linux | linux_kernel | 4.15 ≤ 𝑥 < 4.19.238 |
linux | linux_kernel | 4.20 ≤ 𝑥 < 5.4.189 |
linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.110 |
linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.33 |
linux | linux_kernel | 5.16 ≤ 𝑥 < 5.16.19 |
linux | linux_kernel | 5.17 ≤ 𝑥 < 5.17.2 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
References