Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jvf-xc8m-3fhq

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью

Описание

In the Linux kernel, the following vulnerability has been resolved:

media: iris: Add sanity check for stop streaming

Add sanity check in iris_vb2_stop_streaming. If inst->state is already IRIS_INST_ERROR, we should skip the stream_off operation because it would still send packets to the firmware.

In iris_kill_session, inst->state is set to IRIS_INST_ERROR and session_close is executed, which will kfree(inst_hfi_gen2->packet). If stop_streaming is called afterward, it will cause a crash.

[bod: remove qcom from patch title]

In the Linux kernel, the following vulnerability has been resolved:

media: iris: Add sanity check for stop streaming

Add sanity check in iris_vb2_stop_streaming. If inst->state is already IRIS_INST_ERROR, we should skip the stream_off operation because it would still send packets to the firmware.

In iris_kill_session, inst->state is set to IRIS_INST_ERROR and session_close is executed, which will kfree(inst_hfi_gen2->packet). If stop_streaming is called afterward, it will cause a crash.

[bod: remove qcom from patch title]

Связанные уязвимости

ubuntu
7 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

redhat
7 месяцев назад

No description is available for this CVE.

nvd
7 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS3: 5.5
fstec
9 месяцев назад

Уязвимость функции iris_vb2_stop_streaming() модуля drivers/media/platform/qcom/iris/iris_vb2.c драйвера мультимедийных устройств ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании