[PATCH 0/1 v2][OEM-5.6] CVE-2021-30002 v4l2 memory leak
Tim Gardner
tim.gardner at canonical.com
Thu Apr 8 19:17:06 UTC 2021
Focal:linux-oem-5.6 is the only kernel that does not have this patch.
[SRU Justification]
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device
exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory
leak for large arguments, aka CID-fb18802a338b.
[Test Plan]
Use MPlayer, vlc, or any number of applications that rely on Video4Linux.
[Where problems could occur]
If mis-coded the function could still leak memory.
[Other Info]
Upstream likes the fix. Released in stable kernels:
linux-4.14.y
linux-4.19.y
linux-4.4.y
linux-4.9.y
linux-5.10.y
linux-5.11.y
linux-5.4.y
More information about the kernel-team
mailing list