CVE-2024-35830: media: tc358743: register v4l2 async device only after successful setup
In the Linux kernel, the following vulnerability has been resolved:
media: tc358743: register v4l2 async device only after successful setup
Ensure the device has been setup correctly before registering the v4l2 async device, thus allowing userspace to access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35830?
CVE-2024-35830 has been classified as a moderate severity vulnerability due to its impact on the Linux kernel's media handling.
How do I fix CVE-2024-35830?
To remediate CVE-2024-35830, ensure you upgrade to the patched versions of the Linux kernel specified in the vulnerability description.
What is the impact of CVE-2024-35830?
The impact of CVE-2024-35830 is that it could potentially allow incorrect device registration in the Linux kernel, leading to improper userspace access.
Which versions of the Linux kernel are affected by CVE-2024-35830?
CVE-2024-35830 affects specific versions of the Linux kernel including 5.10.223-1, 5.10.226-1, 6.1.123-1, and others as listed in the documentation.
Is CVE-2024-35830 already fixed in some Linux kernel versions?
Yes, CVE-2024-35830 has been resolved in various updated versions of the Linux kernel.