VDB

CISA-2022-48987

CISA-2022-48987 PUBLISHED

Reported by Linux · Published October 21, 2024

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-dv-timings.c: fix too strict blanking sanity checks Sanity checks were added to verify the v4l2_bt_timings blanking fields in order to avoid integer overflows when userspace passes weird values. But that assumed that userspace would correctly fill in the front porch, backporch and sync values, but sometimes all you know is the total blanking, which is then assigned to just one of these fields. And that can fail with these checks. So instead set a maximum for the total horizontal and vertical blanking and check that each field remains below that. That is still sufficient to avoid integer overflows, but it also allows for more flexibility in how userspace fills in these fields.

Affected Products

VendorProductVersions
LinuxLinux15ded23db134da975b49ea99770de0346c193b24, 3d43b2b8a3cdadd6cef9ac8ef5d156b6214a01c8, 9cf9211635b68e8e0c8cb88d43ca7dc83e4632aa
LinuxLinux4.9.332, 4.14.298, 4.19.264
LinuxLinux5.4.223, 9cf9211635b68e8e0c8cb88d43ca7dc83e4632aa, b4a3a01762ae072c7f6ff2ff53b5019761288346
linuxlinux_kernel4.14.298, 4.19.264, 6.0.7

Timeline

  • Oct 21, 2024 CVE Published
  • May 4, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›