CVE-2021-30002: Medium severity linux kernel vulnerability
A flaw memory leak in the Linux kernel webcam device functionality was found in the way user calls ioctl that triggers videousercopy function. The highest threat from this vulnerability is to system availability.
Other sources
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. videousercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. videousercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments.
Reference: https://bugzilla.suse.com/showbug.cgi?id=1184120
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fb18802a338b36f675a388fc03d2aa504a0d0899
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-30002?
CVE-2021-30002 has a severity level that primarily affects system availability due to a memory leak in the Linux kernel's webcam device functionality.
How do I fix CVE-2021-30002?
To fix CVE-2021-30002, update your Linux kernel to version 5.12 or later, or to the specified remedial versions for Red Hat and Debian systems.
Which Linux versions are affected by CVE-2021-30002?
CVE-2021-30002 affects all versions of the Linux kernel prior to 5.11.3.
What is the impact of CVE-2021-30002 on my system?
The impact of CVE-2021-30002 is a potential memory leak that could lead to decreased system performance and availability.
Is CVE-2021-30002 specific to certain distributions?
Yes, CVE-2021-30002 specifically affects various Linux distributions including Red Hat and Debian, based on the kernel versions they are running.