Impact
In the Linux kernel's media driver for cx231xx devices, geometry changes to the video stream are permitted even while the auxiliary VBI queue is busy. The driver synchronizes geometry information between the video and VBI streams, but the VBI copy routine calculates buffer offsets based on the current width and a latched line count. When an application resizes the VBI plane to a small width and then enlarges the video width, the VBI copy routine writes past the end of the allocated small plane. This results in a heap out‑of‑bounds write whose offset is attacker‑controlled and whose contents come from the device. The overflow can corrupt kernel memory, causing unpredictable behaviour, denial of service, or local privilege escalation for a user with device access.
Affected Systems
The flaw exists in the Linux kernel's cx231xx media driver. All kernel builds containing the buggy driver before the patch commit are affected. Any system that uses a cx231xx‑compatible video capture card and runs the unpatched kernel is at risk. No explicit version range is supplied, but the advisory indicates the vulnerability was fixed by later commits.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % suggests a currently low exploitation likelihood. Exploitation requires a local application that can open the VBI and video device nodes and perform format changes while the VBI stream is active; thus a privileged or authenticated user is needed. The vulnerability is not listed in CISA KEV, so no publicly documented exploit code exists. Nevertheless, the memory corruption could enable kernel‑level privilege escalation if reliably triggered, so the flaw should be treated as a high‑priority local vulnerability.
OpenCVE Enrichment
Debian DLA
Debian DSA