Home

Description

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup variable *nplanes is provided by user via system call argument. The possible value of q_data->fmt->num_planes is 1-3, while the value of *nplanes can be 1-8. The array access by index i can cause array out-of-bounds. Fix this bug by checking *nplanes against the array size.

PUBLISHED Reserved 2025-12-08 | Published 2025-12-08 | Updated 2025-12-08 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 48e4e06e2c5fe1fda283d499f91492eda2248bb9
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before b8e19bf3b4aebd855be01b64674187dcf6d1db51
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 8fbcf730cb89c3647f3365226fe7014118fa93c7
affected

Default status
affected

6.1.30 (semver)
unaffected

6.3.4 (semver)
unaffected

6.4 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/48e4e06e2c5fe1fda283d499f91492eda2248bb9

git.kernel.org/...c/b8e19bf3b4aebd855be01b64674187dcf6d1db51

git.kernel.org/...c/8fbcf730cb89c3647f3365226fe7014118fa93c7

cve.org (CVE-2023-53748)

nvd.nist.gov (CVE-2023-53748)

Download JSON