媒体:uvcvideo:跳过解析 uvc_parse_format 中 UVC_VS_UNDEFINED 类型的帧(CVE-2024-53104)
CVE编号
CVE-2024-53104
利用情况
暂无
补丁情况
N/A
披露时间
2024-12-02
漏洞描述
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
This can lead to out of bounds writes since frames of this type were not
taken into account when calculating the size of the frames buffer in
uvc_parse_streaming.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
文章评论