CVE-2024-35919: media: mediatek: vcodec: adding lock to protect encoder context list
In the Linux kernel, the following vulnerability has been resolved:
media: mediatek: vcodec: adding lock to protect encoder context list
Add a lock for the ctxlist, to avoid accessing a NULL pointer within the 'vpuencipihandler' function when the ctxlist has been deleted due to an unexpected behavior on the SCP IP block.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35919?
CVE-2024-35919 has been classified as a high severity vulnerability due to the potential for NULL pointer dereference.
How do I fix CVE-2024-35919?
To fix CVE-2024-35919, update your Linux kernel to one of the patched versions, specifically 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.10-1, or 6.12.11-1.
Which systems are affected by CVE-2024-35919?
CVE-2024-35919 affects systems running vulnerable versions of the Linux kernel, particularly those associated with the media and mediatek components.
What is the potential impact of exploiting CVE-2024-35919?
Exploiting CVE-2024-35919 could lead to a denial-of-service condition through unexpected crashes in the affected software.
When was CVE-2024-35919 disclosed?
CVE-2024-35919 was disclosed following its resolution in the Linux kernel to enhance security against specific vulnerabilities.