SB2024070203 - Improper Initialization in Linux kernel decoder vdec driver
Published: July 2, 2024 Updated: May 13, 2025
Security Bulletin ID
SB2024070203
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Initialization (CVE-ID: CVE-2024-35921)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper initialization within the vdec_hevc_slice_init() function in drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_hevc_req_multi_if.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/ec25fc3c2c1e8958a51abcfed614f81446d918c4
- https://git.kernel.org/stable/c/521ce0ea7418298d754494fe53263c23c4c78a8e
- https://git.kernel.org/stable/c/97c75ee5de060d271d80109b0c47cb6008439e5b
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.27
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.6