Executive brief
A vulnerability was identified in the Linux kernel's media subsystem, specifically within the component that handles memory-to-memory video processing. A technical error in how the system manages memory during certain failure scenarios can lead to a memory leak. Over time, this could allow a local user to exhaust system resources, potentially leading to a system crash or degraded performance.
Technical details
A memory leak (CWE-401) exists in the v4l2_m2m_register_entity function within drivers/media/v4l2-core/v4l2-mem2mem.c. The vulnerability occurs because the 'entity->name' field is allocated during registration but is not properly deallocated if subsequent error-handling paths are triggered (such as failures in media_entity_pads_init or media_device_register_entity). A local attacker with basic privileges could potentially trigger these error paths repeatedly to exhaust kernel memory, leading to a denial of service. The issue has been resolved by adding kfree() calls to the affected error paths in various stable kernel branches.
Affected products
- Linux Linux Kernel 4.19 to 4.19.311, 4.20 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-05-01: disclosed: CVE published
- 2024-03-26: patched: Fixes committed to stable kernel branches
References
- https://git.kernel.org/stable/c/0175f2d34c85744f9ad6554f696cf0afb5bd04e4
- https://git.kernel.org/stable/c/0c9550b032de48d6a7fa6a4ddc09699d64d9300d
- https://git.kernel.org/stable/c/3dd8abb0ed0e0a7c66d6d677c86ccb188cc39333
- https://git.kernel.org/stable/c/5dc319cc3c4f7b74f7dfba349aa26f87efb52458
- https://git.kernel.org/stable/c/8f94b49a5b5d386c038e355bef6347298aabd211
- https://git.kernel.org/stable/c/90029b9c979b60de5cb2b70ade4bbf61d561bc5d
- https://git.kernel.org/stable/c/9c23ef30e840fedc66948299509f6c2777c9cf4f