CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's Thunderbolt implementation, specifically in the handling of bandwidth group reservations. An improper indexing issue allows access to an out-of-bounds array element, potentially leading to miscalculated bandwidth allocations. Linux system administrators and developers utilizing Thunderbolt technology should prioritize addressing this vulnerability to ensure proper bandwidth management and system stability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth group reservation indexing Valid bandwidth group IDs range from 1 through MAX_GROUPS, while Group ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly to index its local group_reserved[] array. The array currently has MAX_GROUPS entries, so its valid indices are 0 through MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one element past the end, and the final group's reserved bandwidth is not included when the array is summed. Give group_reserved[] MAX_GROUPS + 1 entries so direct Group ID indexing covers the reserved ID 0 and valid IDs 1 through MAX_GROUPS.