First published: Mon Nov 04 2019(Updated: )
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <=5.3.8 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
openSUSE Leap | =15.1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Cloud Backup | ||
Netapp Data Availability Services | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
Netapp Element Software | ||
Netapp Hci Management Node | ||
Netapp Solidfire | ||
Netapp Steelstore Cloud Integrated Storage | ||
Broadcom Fabric Operating System | ||
Netapp A700s Firmware | ||
Netapp A700s | ||
Netapp 8300 Firmware | ||
Netapp 8300 | ||
Netapp 8700 Firmware | ||
Netapp 8700 | ||
Netapp A400 Firmware | ||
Netapp A400 | ||
Netapp H610s Firmware | ||
Netapp H610s | ||
Debian Debian Linux | =8.0 | |
Linux Linux kernel | >=3.18<4.4.204 | |
Linux Linux kernel | >=4.5<4.9.204 | |
Linux Linux kernel | >=4.10<4.14.157 | |
Linux Linux kernel | >=4.15<4.19.87 | |
Linux Linux kernel | >=4.20<5.3.14 | |
Linux Linux kernel | >=5.4<5.4.1 | |
All of | ||
Netapp A700s Firmware | ||
Netapp A700s | ||
All of | ||
Netapp 8300 Firmware | ||
Netapp 8300 | ||
All of | ||
Netapp 8700 Firmware | ||
Netapp 8700 | ||
All of | ||
Netapp A400 Firmware | ||
Netapp A400 | ||
All of | ||
Netapp H610s Firmware | ||
Netapp H610s | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.9-1 6.12.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.