CVE Database
/

CVE-2024-50288

Back to search

CVE-2024-50288

Published: Nov 19, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix buffer overwrite when using > 32 buffers The maximum number of buffers that can be requested was increased to 64 for the video capture queue. But video capture used a must_blank array that was still sized for 32 (VIDEO_MAX_FRAME). This caused an out-of-bounds write when using buffer indices >= 32. Create a new define MAX_VID_CAP_BUFFERS that is used to access the must_blank array and set max_num_buffers for the video capture queue. This solves a crash reported by: https://bugzilla.kernel.org/show_bug.cgi?id=219258

VendorProductVersions

Linux

Linux

affected
cea70ed416b428f8214be196d62cc7ffaa11f1b8 - < e6bacd8f2178b22859fe6d9f755f19dfcd9d3862
affected
cea70ed416b428f8214be196d62cc7ffaa11f1b8 - < 96d8569563916fe2f8fe17317e20e43f54f9ba4b

Linux

Linux

affected
6.8
unaffected
0 - < 6.8
unaffected
6.11.8 - <= 6.11.*
unaffected
6.12 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now