7.8
CVE-2026-89894
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:31:56
- Zuletzt bearbeitet 16.09.2026 15:18:15
- Erkennungen
media: cx231xx: reject geometry changes while the VBI queue is busy
In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the VBI queue is busy vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide dev->width / dev->norm but only refuse the change when the *video* queue (dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry: cx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm, the VBI videobuf2 plane is sized from dev->width / dev->norm in vbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then recomputes the destination offset from the *live* dev->width and the latched lines_per_field on every URB completion: offset = lines_completed * (dev->width << 1) + ...; if (dma_q->current_field == 2) offset += dev->width * 2 * dma_q->lines_per_field; memcpy(plane + offset, p_buffer, lencopy); Because the VBI node shares video_ioctl_ops with the video node, an application can size a small VBI plane (REQBUFS/QBUF with a small width, or with the NTSC standard), then enlarge dev->width (or switch dev->norm to PAL) through the video node while the VBI stream is running -- the change is allowed because only dev->vidq is checked -- and let the device deliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the offset with the larger geometry and memcpy()s past the end of the smaller plane that was already allocated, a heap out-of-bounds write whose offset is attacker-chosen and whose contents come from the device. The per-field guard in cx231xx_copy_vbi_line() does not help: it bounds the copy against the latched lines_per_field, not the plane's real capacity, and vb2 does not re-run buf_prepare() for an already prepared buffer. Refuse the format/standard change when the VBI queue is busy as well, so the geometry cannot change underneath an allocated VBI buffer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
aa3314506deb9703bcf0e889db08959440228fbf
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
90d50648af36a1fbf5dbc99238de6fd0e58a13e0
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
a5dd3d7fba358ff9486f3f51b2a9038348c0970a
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
1d1079db8d1807e259a1d2679ed314949797aad9
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
7087bef6510c7df5df0b19192633b8ecc0f33a6f
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
a636c72c7f522d984fa498fc0631f33a2d0be3fd
Status
affected
Version
7c617138b8254a6bb60bfb5b8fc53eb8b3d6c3ab
Version <
627a121c15fe05a541f44d86016294b80bada75d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.5
Status
affected
Version
0
Version <
5.5
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/aa3314506deb9703bcf0e889db08959440228fbf
https://git.kernel.org/stable/c/90d50648af36a1fbf5dbc99238de6fd0e58a13e0
https://git.kernel.org/stable/c/a5dd3d7fba358ff9486f3f51b2a9038348c0970a
https://git.kernel.org/stable/c/54ac6df8b8d97eddc3ae97fd2045bdedc8541b6d
https://git.kernel.org/stable/c/1d1079db8d1807e259a1d2679ed314949797aad9
https://git.kernel.org/stable/c/7087bef6510c7df5df0b19192633b8ecc0f33a6f
https://git.kernel.org/stable/c/a636c72c7f522d984fa498fc0631f33a2d0be3fd
https://git.kernel.org/stable/c/627a121c15fe05a541f44d86016294b80bada75d