media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.3%
exploitation probability
0.3%top 85% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com
On the case tmp_dcim=1, the index of buffer is miscalculated.
This generate a NULL pointer dereference later.
So let's fix the calcul and add a check to prevent this to reappear.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/20811bbe685ca3eddd34b0c750860427d7030910https://git.kernel.org/stable/c/20db2ed1e2f9fcd417fa67853e5154f0c2537d6chttps://git.kernel.org/stable/c/7e76f3ed7ab2ae026c6ef9cc23096a7554af8c52https://git.kernel.org/stable/c/8dce4b265a5357731058f69645840dabc718c687https://git.kernel.org/stable/c/bafec1a6ba4b187a7fcdcfce0faebdc623d4ef8e