Executive brief
The Linux kernel's camera subsystem (camss) driver failed to properly clean up buffered data when video streaming initialization encountered errors, such as when media pipeline validation failed. This could cause kernel warnings and resource leaks when users attempted to start video streaming under invalid configurations. The fix ensures buffers are properly returned to the system whenever streaming fails to start.
Technical details
This vulnerability is a resource management error in the camss driver's video_start_streaming() function. When media_pipeline_start() fails (e.g., due to link validation errors returning EPIPE), the function would return immediately without calling the flush_buffers operation to clean up queued video buffers. This left buffers in an inconsistent state, triggering kernel warnings in videobuf2-core and potentially causing memory leaks. The fix adds a goto label to ensure flush_buffers is always called during error exit paths. The vulnerability affects the media subsystem and is triggered during local V4L2 ioctl operations (STREAMON), requiring no special privileges beyond access to video device files.
Affected products
- Linux Linux kernel 5.0 and later (prior to fix in 2022-07)
Timeline
- 2025-12-24: disclosed: CVE-2022-50757 published
- 2022-07-04: patched: Upstream fix committed by Vladimir Zapolskiy