Bug 2334450 (CVE-2024-56571)
Summary: | CVE-2024-56571 kernel: media: uvcvideo: Require entities to have a non-zero unique ID | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | dfreiber, drow, jburrell, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
[REJECTED CVE] A vulnerability was identified in the Linux kernel's uvcvideo driver, where media entities could be allocated with an ID of 0 or duplicate IDs, violating the UVC 1.1+ specification. This flaw allowed malformed USB video device descriptors to create invalid media entity chains, potentially causing kernel warnings and crashes due to entities referencing themselves or forming backward loops. An attacker with physical or emulated USB device access could exploit this by crafting a malicious UVC device that triggers kernel warnings or system instability.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
OSIDB Bzimport
2024-12-27 15:02:50 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024122716-CVE-2024-56571-2bbc@gregkh/T This CVE has been rejected upstream: https://lore.kernel.org/linux-cve-announce/2025021341-REJECTED-5fa1@gregkh/ |