Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-20369

Опубликовано: 23 янв. 2022
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel

An out-of-bounds write flaw was found in the Linux kernel’s UVC camera and similar device driver code due to improper input validation in the v4l2-mem2mem.c source code in how a user calls ioctl VIDIOC_QUERYBUF with mmap. This issue occurs if the capture buffer mapped directly from the userspace uses values from DQBUF, which returns an error. This flaw allows a local user to crash or escalate their privileges on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 9kernelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2137505kernel: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls

EPSS

Процентиль: 6%
0.00164
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 4 лет назад

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel

CVSS3: 6.7
nvd
около 4 лет назад

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel

CVSS3: 6.7
debian
около 4 лет назад

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bou ...

CVSS3: 6.7
github
около 4 лет назад

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel

CVSS3: 6.7
fstec
больше 4 лет назад

Уязвимость функции v4l2_m2m_querybuf компонента v4l2-mem2mem.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании, повысить свои привилегии или выполнить произвольный код

EPSS

Процентиль: 6%
0.00164
Низкий

6.7 Medium

CVSS3