CVE-2024-50288
Published: Nov 19, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix buffer overwrite when using > 32 buffers The maximum number of buffers that can be requested was increased to 64 for the video capture queue. But video capture used a must_blank array that was still sized for 32 (VIDEO_MAX_FRAME). This caused an out-of-bounds write when using buffer indices >= 32. Create a new define MAX_VID_CAP_BUFFERS that is used to access the must_blank array and set max_num_buffers for the video capture queue. This solves a crash reported by: https://bugzilla.kernel.org/show_bug.cgi?id=219258
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected cea70ed416b428f8214be196d62cc7ffaa11f1b8 - < e6bacd8f2178b22859fe6d9f755f19dfcd9d3862affected cea70ed416b428f8214be196d62cc7ffaa11f1b8 - < 96d8569563916fe2f8fe17317e20e43f54f9ba4b |
Linux | Linux | affected 6.8unaffected 0 - < 6.8unaffected 6.11.8 - <= 6.11.*unaffected 6.12 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now