Description
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count can get incremented to value more than MAX_CODEC_NUM, there can be OOB access. Reset the count so that it always starts from beginning.
Product status
1a73374a04e555103e5369429a30999114001dda (git) before e5133a0b25463674903fdc0528e0a29b7267130e
1a73374a04e555103e5369429a30999114001dda (git) before 2b8b9ea4e26a501eb220ea189e42b4527e65bdfa
1a73374a04e555103e5369429a30999114001dda (git) before 1ad6aa1464b8a5ce5c194458315021e8d216108e
1a73374a04e555103e5369429a30999114001dda (git) before 26bbedd06d85770581fda5d78e78539bb088fad1
1a73374a04e555103e5369429a30999114001dda (git) before d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45
1a73374a04e555103e5369429a30999114001dda (git) before 53e376178ceacca3ef1795038b22fc9ef45ff1d3
1a73374a04e555103e5369429a30999114001dda (git) before b2541e29d82da8a0df728aadec3e0a8db55d517b
1a73374a04e555103e5369429a30999114001dda (git) before cb5be9039f91979f8a2fac29f529f746d7848f3e
1a73374a04e555103e5369429a30999114001dda (git) before 172bf5a9ef70a399bb227809db78442dc01d9e48
4.19
Any version before 4.19
5.4.293 (semver)
5.10.237 (semver)
5.15.181 (semver)
6.1.135 (semver)
6.6.88 (semver)
6.12.24 (semver)
6.13.12 (semver)
6.14.3 (semver)
6.15 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/05/msg00045.html
lists.debian.org/debian-lts-announce/2025/05/msg00030.html
git.kernel.org/...c/e5133a0b25463674903fdc0528e0a29b7267130e
git.kernel.org/...c/2b8b9ea4e26a501eb220ea189e42b4527e65bdfa
git.kernel.org/...c/1ad6aa1464b8a5ce5c194458315021e8d216108e
git.kernel.org/...c/26bbedd06d85770581fda5d78e78539bb088fad1
git.kernel.org/...c/d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45
git.kernel.org/...c/53e376178ceacca3ef1795038b22fc9ef45ff1d3
git.kernel.org/...c/b2541e29d82da8a0df728aadec3e0a8db55d517b
git.kernel.org/...c/cb5be9039f91979f8a2fac29f529f746d7848f3e
git.kernel.org/...c/172bf5a9ef70a399bb227809db78442dc01d9e48