In the Linux kernel, the following vulnerability has been resolved:
ACPI: LPIT: Avoid u32 multiplication overflow
In lpit_update_residency() there is a possibility of overflow in multiplication, if tsc_khz is large enough (> UINT_MAX/1000).
Change multiplication to mul_u32_u32().
Found by Linux Verification Center (linuxtesting.org) with SVACE.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.15 | 4.19.306 |
| linux / linux_kernel | 4.20 | 5.4.268 |
| linux / linux_kernel | 5.5 | 5.10.209 |
| linux / linux_kernel | 5.11 | 5.15.148 |
| linux / linux_kernel | 5.16 | 6.1.75 |
| linux / linux_kernel | 6.2 | 6.6.14 |
| linux / linux_kernel | 6.7 | 6.7.2 |
| debian / debian_linux | 10.0 | 10.0.x |