Severity
5.5MEDIUMNVD
CISA9.8
EPSS
3.4%
top 12.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateJul 12

Description

An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel6.76.9.7+3
Debianlinux/linux_kernel< 5.10.113-1+6
CVEListV5linux/linux590577a4e5257ac3ed72999a94666ad6ba8f24bceeb62bb4ca22db17f7dfe8fb8472e0442df3d92f+4
debiandebian/linux< linux 5.17.3-1 (bookworm)+1
debiandebian/linux-6.1< linux 6.1.133-1 (bookworm)

Patches

🔴Vulnerability Details

5
OSV
CVE-2024-40973: In the Linux kernel, the following vulnerability has been resolved: media: mtk-vcodec: potential null pointer deference in SCP The return value of dev2024-07-12
GHSA
GHSA-g7g4-7563-37xc: In the Linux kernel, the following vulnerability has been resolved: media: mtk-vcodec: potential null pointer deference in SCP The return value of d2024-07-12
Kernel
media: mtk-vcodec: potential null pointer deference in SCP2024-01-18
GHSA
GHSA-mrvv-fwrw-5pgv: An issue was discovered in the Linux kernel through 52022-12-14
OSV
CVE-2022-3113: An issue was discovered in the Linux kernel through 52022-12-14

📋Vendor Advisories

6
Red Hat
kernel: media: mtk-vcodec: potential null pointer deference in SCP2024-07-12
Debian
CVE-2024-40973: linux - In the Linux kernel, the following vulnerability has been resolved: media: mtk-...2024
Red Hat
kernel: media: mtk-vcodec: NULL pointer dereference in mtk_vcodec_fw_vpu_init()2022-12-13
Microsoft
An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will2022-12-13
CISA
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability2022-04-13