Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-36785

Опубликовано: 28 фев. 2024
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.

Отчет

A use-after-free/double-free flaw in the Linux kernel's Intel atomisp camera driver (staging): atomisp_alloc_css_stat_bufs() can free an s3a statistics buffer that is also freed via the asd->s3a_stats list, leading to a double free and use-after-free. Exploitation requires privileged local access to the atomisp V4L2 device, so Red Hat rates this Low (4.4, denial of service only), below external scores (NIST/CVE.org 7.8). Red Hat Enterprise Linux kernels do not build the atomisp staging driver (CONFIG_VIDEO_ATOMISP is not set), so supported Red Hat products are not affected.

Меры по смягчению последствий

The atomisp driver is not built or shipped in Red Hat Enterprise Linux kernels (CONFIG_VIDEO_ATOMISP is disabled), so the vulnerable code path cannot be reached. Where the driver is present, blacklisting/unloading the atomisp module and restricting access to the ISP /dev/video device nodes to trusted users removes exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2266954kernel: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs()

EPSS

Процентиль: 13%
0.00224
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.

CVSS3: 7.8
nvd
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.

CVSS3: 7.8
debian
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: m ...

CVSS3: 7.8
github
больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.

CVSS3: 7.8
fstec
больше 5 лет назад

Уязвимость функции atomisp_alloc_css_stat_bufs() модуля drivers/staging/media/atomisp/pci/atomisp_ioctl.c - драйвера поддержки устройств линейки Intel Atom ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании.

EPSS

Процентиль: 13%
0.00224
Низкий

4.4 Medium

CVSS3