Impact
The Linux kernel media/vicodec driver incorrectly calculates capture buffer size for the FWHT encoder. When a four‑component pixel format triggers the unencoded fallback path, the driver writes the encoded frame plus a header into a buffer that is insufficient, resulting in an out‑of‑bounds write. This heap corruption flaw (CWE‑787) could allow an attacker to corrupt the kernel’s memory image, potentially leading to privilege escalation or causing a kernel panic and denial‑of‑service.
Affected Systems
The vulnerability exists in the media/vicodec driver within the Linux kernel, as included in all kernel releases prior to the patch that increases the buffer‑size multiplier to four. Any Linux system that ships the unpatched driver and exposes /dev/video* device nodes is affected. Systems that have updated impacted.
Risk and Exploitability
The CVSS score for this flaw is 7.8, indicating a moderate to high severity, while the EPSS score is below 1%, suggesting a currently low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is local: an attacker who can write crafted frames to a /dev/video* device node may trigger the out‑of‑bounds write, corrupt kernel memory, and achieve privilege escalation or denial‑of‑service.
OpenCVE Enrichment
Debian DSA