cbcvebase.
CVE-2024-35919
published 2024-05-19

CVE-2024-35919: In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the…

PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the ctx_list, to avoid accessing a NULL pointer within the 'vpu_enc_ipi_handler' function when the ctx_list has been deleted due to an unexpected behavior on the SCP IP block.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux
linuxlinux>= 1972e32431ed14682909ad568c6fd660572ae6ab < 41671f0c0182b2bae74ca7e3b0f155559e3e2fc541671f0c0182b2bae74ca7e3b0f155559e3e2fc5
linuxlinux>= 1972e32431ed14682909ad568c6fd660572ae6ab < 51c84a8aac6e3b59af2b0e92ba63cabe2e641a2d51c84a8aac6e3b59af2b0e92ba63cabe2e641a2d
linuxlinux>= 1972e32431ed14682909ad568c6fd660572ae6ab < afaaf3a0f647a24a7bf6a2145d8ade37baaf75adafaaf3a0f647a24a7bf6a2145d8ade37baaf75ad
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 6.6 < 6.6.276.6.27
linuxlinux_kernel>= 6.7 < 6.8.66.8.6

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.