CVE-2021-46943 | Date: (C)2024-02-28 (M)2024-04-19 |
In the Linux kernel, the following vulnerability has been resolved:
media: staging/intel-ipu3: Fix set_fmt error handling
If there in an error during a set_fmt, do not overwrite the previous
sizes with the invalid config.
Without this patch, v4l2-compliance ends up allocating 4GiB of RAM and
causing the following OOPs
[ 38.662975] ipu3-imgu 0000:00:05.0: swiotlb buffer is full (sz: 4096 bytes)
[ 38.662980] DMA: Out of SW-IOMMU space for 4096 bytes at device 0000:00:05.0
[ 38.663010] general protection fault: 0000 [#1] PREEMPT SMP
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V3 Severity: | CVSS V2 Severity: |
CVSS Score : 7.8 | CVSS Score : |
Exploit Score: 1.8 | Exploit Score: |
Impact Score: 5.9 | Impact Score: |
|
CVSS V3 Metrics: | CVSS V2 Metrics: |
Attack Vector: LOCAL | Access Vector: |
Attack Complexity: LOW | Access Complexity: |
Privileges Required: LOW | Authentication: |
User Interaction: NONE | Confidentiality: |
Scope: UNCHANGED | Integrity: |
Confidentiality: HIGH | Availability: |
Integrity: HIGH | |
Availability: HIGH | |
| |