A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures Upstream commit: https://github.com/torvalds/linux/commit/a7b2df76b42bdd026e3106cf2ba97db41345a177
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1775117]
Statement: This issue is rated as having Low impact because of the preconditions needed to trigger the resource cleanup code path (system-wide out-of-memory condition).
Mitigation: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module cx23885. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 .