In the Linux kernel, the following vulnerability has been resolved:
nvmem: core: limit cell sysfs permissions to main attribute ones
The cell sysfs attribute should not provide more access to the nvmem data than the main attribute itself. For example if nvmeconfig::rootonly was set, the cell attribute would still provide read access to everybody.
Mask out permissions not available on the main attribute.
[
{
"digest": {
"length": 1301.0,
"function_hash": "290114771458786039327156757359656828988"
},
"target": {
"function": "nvmem_populate_sysfs_cells",
"file": "drivers/nvmem/core.c"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@aa066afaaac32caf2160d58d4e3010ee04421c62",
"signature_version": "v1",
"id": "CVE-2024-41029-1801e503"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"221264506616910645219562159980818420279",
"303265297090842029194551167022040963384",
"179480714115571017466536993973908999146",
"270444839728930399291465620545738905441"
]
},
"target": {
"file": "drivers/nvmem/core.c"
},
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@aa066afaaac32caf2160d58d4e3010ee04421c62",
"signature_version": "v1",
"id": "CVE-2024-41029-5dc52fa0"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"221264506616910645219562159980818420279",
"303265297090842029194551167022040963384",
"179480714115571017466536993973908999146",
"270444839728930399291465620545738905441"
]
},
"target": {
"file": "drivers/nvmem/core.c"
},
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6bef98bafd82903a8d461463f9594f19f1fd6a85",
"signature_version": "v1",
"id": "CVE-2024-41029-71fc113d"
},
{
"digest": {
"length": 1301.0,
"function_hash": "290114771458786039327156757359656828988"
},
"target": {
"function": "nvmem_populate_sysfs_cells",
"file": "drivers/nvmem/core.c"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6bef98bafd82903a8d461463f9594f19f1fd6a85",
"signature_version": "v1",
"id": "CVE-2024-41029-c0253d9b"
}
]