
Cloud Vulnerability DB
A community-led vulnerabilities database
In the Linux kernel, a vulnerability (CVE-2022-48945) was discovered in the media subsystem's vivid driver. The issue was found by syzkaller and involves a boundary check failure in the compose size handling. The vulnerability was reported when a page fault occurred at address ffffc9000a3b1000 during supervisor write access in kernel mode (Ubuntu).
The vulnerability occurs because the code fails to check boundary conditions after adjusting compose->height in the V4L2_SEL_TGT_CROP case. This leads to a page fault with error code 0x0002 (not-present page) in the vivid driver. The issue manifests in the memcpy_erms function and affects the video capture functionality of the vivid test driver (Kernel Commit).
When triggered, this vulnerability results in a kernel page fault and system crash, potentially leading to denial of service conditions. The issue affects the kernel's media subsystem, specifically the vivid test driver used for video capture operations.
The issue has been fixed by adding a v4l2_rect_map_inside() check to properly validate the compose boundary against the format rectangle. The fix has been implemented across multiple kernel versions, including Ubuntu's kernel packages for various releases (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."