Hide Forgot
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service. Reference and upstream commit: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dea37a97265588da604c6ba80160a287b72c7bfd
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1794400]
This was fixed for Fedora in the 5.1.6 stable kernel update.
Mitigation: To mitigate this issue, prevent module cpia2 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.