SB20251230280 - Integer underflow in Linux kernel saa7146 av7110 driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2023-54284)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer underflow within the write_ts_to_decoder() function in drivers/staging/media/deprecated/saa7146/av7110/av7110_av.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/423350af9e27f005611bd881b1df2cab66de943d
- https://git.kernel.org/stable/c/620b983589e0223876bf1463b01100a9c67b56ba
- https://git.kernel.org/stable/c/6606e2404ee9e20a3ae5b42fc3660d41b739ed3e
- https://git.kernel.org/stable/c/6680af5be9f08d830567e9118f76d3e64684db8f
- https://git.kernel.org/stable/c/77eeb4732135c18c2fdfab80839645b393f3e774
- https://git.kernel.org/stable/c/7b93ab60fe9ed04be0ff155bc30ad39dea23e22b
- https://git.kernel.org/stable/c/86ba65e5357bfbb6c082f68b265a292ee1bdde1d
- https://git.kernel.org/stable/c/ca4ce92e3ec9fd3c7c936b912b95c53331d5159c
- https://git.kernel.org/stable/c/eed9496a0501357aa326ddd6b71408189ed872eb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.315
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.283
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.211
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.111
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.243
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.28
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.15
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4