UBUNTU-CVE-2016-4568
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call.
02 / AFFECTED SOFTWARE
Affected packages
18 explicit affected versions
38 explicit affected versions
17 explicit affected versions
13 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call.
05 / REFERENCES
Further evidence
- https://git.linuxtv.org/sailus/media_tree.git/log/?h=vb2-overwrite-fix-error-on-fixes-v2
- https://patchwork.linuxtv.org/patch/34284/
- https://ubuntu.com/security/CVE-2016-4568
- https://ubuntu.com/security/notices/USN-3161-1
- https://ubuntu.com/security/notices/USN-3161-2
- https://ubuntu.com/security/notices/USN-3161-3
- https://ubuntu.com/security/notices/USN-3161-4
- https://www.cve.org/CVERecord?id=CVE-2016-4568