VDB

CISA-2023-52491

CISA-2023-52491 PUBLISHED

Reported by Linux · Published February 29, 2024

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run In mtk_jpeg_probe, &jpeg->job_timeout_work is bound with mtk_jpeg_job_timeout_work. In mtk_jpeg_dec_device_run, if error happens in mtk_jpeg_set_dec_dst, it will finally start the worker while mark the job as finished by invoking v4l2_m2m_job_finish. There are two methods to trigger the bug. If we remove the module, it which will call mtk_jpeg_remove to make cleanup. The possible sequence is as follows, which will cause a use-after-free bug. CPU0 CPU1 mtk_jpeg_dec_... | start worker | |mtk_jpeg_job_timeout_work mtk_jpeg_remove | v4l2_m2m_release | kfree(m2m_dev); | | | v4l2_m2m_get_curr_priv | m2m_dev->curr_ctx //use If we close the file descriptor, which will call mtk_jpeg_release, it will have a similar sequence. Fix this bug by starting timeout worker only if started jpegdec worker successfully. Then v4l2_m2m_job_finish will only be called in either mtk_jpeg_job_timeout_work or mtk_jpeg_dec_device_run.

Affected Products

VendorProductVersions
LinuxLinuxb2f0d2724ba477d326e9d654d4db1c93e98f8b93, b2f0d2724ba477d326e9d654d4db1c93e98f8b93, b2f0d2724ba477d326e9d654d4db1c93e98f8b93
LinuxLinux4.12, 0, 5.10.210
linuxlinux_kernel4.12, 4.12, 4.12
LinuxLinuxb2f0d2724ba477d326e9d654d4db1c93e98f8b93, b2f0d2724ba477d326e9d654d4db1c93e98f8b93, b2f0d2724ba477d326e9d654d4db1c93e98f8b93

Timeline

  • Feb 29, 2024 CVE Published
  • May 4, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›