cbcvebase.
CVE-2024-39481
published 2024-07-05

CVE-2024-39481: In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links, even if they are not between pads. This causes a crash with, e.g. a MEDIA_LNK_FL_ANCILLARY_LINK link. Fix this by allowing the walk to proceed only for MEDIA_LNK_FL_DATA_LINK links.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= ae219872834a32da88408a92a4b4745c11f5a7ce < 788fd0f11e45ae8d3a8ebbd3452a6e83f92db376788fd0f11e45ae8d3a8ebbd3452a6e83f92db376
linuxlinux>= ae219872834a32da88408a92a4b4745c11f5a7ce < e80d9db99b7b6c697d8d952dfd25c3425cf61499e80d9db99b7b6c697d8d952dfd25c3425cf61499
linuxlinux>= ae219872834a32da88408a92a4b4745c11f5a7ce < bee9440bc0b6b3b7432f7bfde28656262a3484a2bee9440bc0b6b3b7432f7bfde28656262a3484a2
linuxlinux>= ae219872834a32da88408a92a4b4745c11f5a7ce < 8a9d420149c477e7c97fbd6453704e4612bdd3fa8a9d420149c477e7c97fbd6453704e4612bdd3fa
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.1 < 6.1.946.1.94
linuxlinux_kernel>= 6.6 < 6.6.346.6.34
linuxlinux_kernel>= 6.9 < 6.9.56.9.5
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.