An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints.
Reference and upstream commit:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1833446]
This was fixed for Fedora with the 5.5.14 stable kernel updates.
In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module gspca_ov519. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 .
This issue is rated as having Low impact because of the preconditions needed to trigger the issue (physical access).