CVE-2024-43831: media: mediatek: vcodec: Handle invalid decoder vsi
Published Aug 17, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
media: mediatek: vcodec: Handle invalid decoder vsi
Handle an invalid decoder vsi in vpudecinit to ensure the decoder vsi is valid for future use.
Affected Software
4 affected componentsFixes available
debian/linux<=5.10.223-1, <=5.10.234-1, <=6.1.129-1
6.1.135-16.12.25-16.12.27-1
Linux Linux kernel>=4.10<6.1.131
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3
Remediation
Event History
Aug 17, 2024
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
Description
Data Sourced
via NVD·10:15 AM
Description
Data Sourced
via NVD·10:15 AM
RemedySeverityAffected Software
May 1, 2025
Data Sourced
via Ubuntu·07:38 PM
RemedyDescriptionSeverityAffected Software
Oct 12, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43831?
CVE-2024-43831 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-43831?
To fix CVE-2024-43831, update your Linux kernel packages to versions 6.12.11-1 or 6.12.12-1 or later.
3
Which Linux kernel versions are affected by CVE-2024-43831?
CVE-2024-43831 affects several Linux kernel versions, including up to 5.10.226-1 and 6.1.123-1.
4
What issue does CVE-2024-43831 address?
CVE-2024-43831 addresses a vulnerability related to handling an invalid decoder vsi in the MediaTek video codec.
5
Is there an exploit available for CVE-2024-43831?
As of now, there is no publicly disclosed exploit for CVE-2024-43831.