В ядре Linux устранена следующая уязвимость:
медиа: vicodec: исправлена запись за пределами допустимого диапазона в кодировщике FWHT.
vidioc_s_fmt_vid_out() определяет размер буфера CAPTURE кодировщика из
сжатый дескриптор pixfmt_fwht, у которого sizeimage_mult равен 3:
coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame()
кодирует одну плоскость для каждого компонента, а несжимаемая плоскость принимает
Путь FWHT_FRAME_UNENCODED в encode_plane(), дословное копирование плоскости.
В 4-компонентном формате пикселей все четыре плоскости имеют полное разрешение.
(width_div == height_div == 1), поэтому кадр, который заставляет каждую плоскость
через незакодированную резервную запись
sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h байт, переполнение
самолет с помощью coded_w * coded_h, что может привести к повреждению
соседней кучи памяти ядра.
Увеличьте значение pixfmt_fwht.sizeimage_mult с 3 до 4, чтобы оно соответствовало самому большому значению.
компонент_номер среди поддерживаемых необработанных форматов, поэтому буфер захвата
всегда достаточно большой для незакодированного резервного варианта.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: media: vicodec: fix out-of-bounds write in FWHT encoder vidioc_s_fmt_vid_out() sizes the encoder CAPTURE buffer from the compressed descriptor pixfmt_fwht, whose sizeimage_mult is 3: coded_w * coded_h * 3 + sizeof(struct fwht_cframe_hdr). fwht_encode_frame() encodes one plane per component, and an incompressible plane takes the FWHT_FRAME_UNENCODED path in encode_plane(), copying the plane verbatim. For a 4-component pixel format all four planes are full resolution (width_div == height_div == 1), so a frame that forces every plane through the unencoded fallback writes sizeof(struct fwht_cframe_hdr) + 4 * coded_w * coded_h bytes, overrunning the plane by coded_w * coded_h, which can result in corruption of adjacent kernel heap memory. Bump pixfmt_fwht.sizeimage_mult from 3 to 4, matching the largest components_num among the supported raw formats, so the capture buffer is always large enough for the unencoded fallback.
Характеристики атаки
Последствия
Строка CVSS v3.1
Уязвимые продукты 4
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
5.0
|
6.12.109
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
5.0
|
6.18.50
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
5.0
|
7.2.4
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
|
5.0
|
7.3-rc1
|