Junglewise Threat Intelligence

CVE-2022-50757: Linux kernel camss media driver resource cleanup error handling

CVE-2022-50757 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's camera subsystem (camss) driver failed to properly clean up buffered data when video streaming initialization encountered errors, such as when media pipeline validation failed. This could cause kernel warnings and resource leaks when users attempted to start video streaming under invalid configurations. The fix ensures buffers are properly returned to the system whenever streaming fails to start.

Technical details

This vulnerability is a resource management error in the camss driver's video_start_streaming() function. When media_pipeline_start() fails (e.g., due to link validation errors returning EPIPE), the function would return immediately without calling the flush_buffers operation to clean up queued video buffers. This left buffers in an inconsistent state, triggering kernel warnings in videobuf2-core and potentially causing memory leaks. The fix adds a goto label to ensure flush_buffers is always called during error exit paths. The vulnerability affects the media subsystem and is triggered during local V4L2 ioctl operations (STREAMON), requiring no special privileges beyond access to video device files.

Affected products

  • Linux Linux kernel 5.0 and later (prior to fix in 2022-07)

Timeline

  • 2025-12-24: disclosed: CVE-2022-50757 published
  • 2022-07-04: patched: Upstream fix committed by Vladimir Zapolskiy

References

Related threats