Описание
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.
Отчет
A use-after-free/double-free flaw in the Linux kernel's Intel atomisp camera driver (staging): atomisp_alloc_css_stat_bufs() can free an s3a statistics buffer that is also freed via the asd->s3a_stats list, leading to a double free and use-after-free. Exploitation requires privileged local access to the atomisp V4L2 device, so Red Hat rates this Low (4.4, denial of service only), below external scores (NIST/CVE.org 7.8). Red Hat Enterprise Linux kernels do not build the atomisp staging driver (CONFIG_VIDEO_ATOMISP is not set), so supported Red Hat products are not affected.
Меры по смягчению последствий
The atomisp driver is not built or shipped in Red Hat Enterprise Linux kernels (CONFIG_VIDEO_ATOMISP is disabled), so the vulnerable code path cannot be reached. Where the driver is present, blacklisting/unloading the atomisp module and restricting access to the ISP /dev/video device nodes to trusted users removes exposure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | ||
| Red Hat Enterprise Linux 9 | kernel | Not affected | ||
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.4 Medium
CVSS3
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.
In the Linux kernel, the following vulnerability has been resolved: m ...
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.
Уязвимость функции atomisp_alloc_css_stat_bufs() модуля drivers/staging/media/atomisp/pci/atomisp_ioctl.c - драйвера поддержки устройств линейки Intel Atom ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании.
EPSS
4.4 Medium
CVSS3