In the Linux kernel, the following vulnerability has been resolved:
media: staging/intel-ipu3: Fix set_fmt error handling
If there in an error during a set_fmt, do not overwrite the previous sizes with the invalid config.
Without this patch, v4l2-compliance ends up allocating 4GiB of RAM and causing the following OOPs
[ 38.662975] ipu3-imgu 0000:00:05.0: swiotlb buffer is full (sz: 4096 bytes) [ 38.662980] DMA: Out of SW-IOMMU space for 4096 bytes at device 0000:00:05.0 [ 38.663010] general protection fault: 0000 [#1] PREEMPT SMP
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 27, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2024 |
| Suse | — | Upgrade kernel-preempt-develUpgrade kernel-sourceUpgrade kernel-symsUpgrade kernel-develUpgrade kernel-64kbUpgrade kernel-64kb-develUpgrade kernel-default-develUpgrade kernel-preemptUpgrade kernel-zfcpdumpUpgrade kernel-obs-buildUpgrade kernel-default-baseUpgrade kernel-docsUpgrade kernel-macrosUpgrade kernel-defaultUpgrade reiserfs-kmp-default | Aug 9, 2024 | Feb 27, 2024 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-raspiUpgrade linux-oracleUpgrade linux-gcp-fipsUpgrade linux-aws-fipsUpgrade linux-hwe-5.4Upgrade linux-fipsUpgrade linux-kvmUpgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-azure-5.4Upgrade linux-gcpUpgrade linux-aws-5.4Upgrade linux-awsUpgrade linuxUpgrade linux-azure-fipsUpgrade linux-gkeopUpgrade linux-gcp-5.4Upgrade linux-oracle-5.4 | Nov 19, 2024 | Feb 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub