SB2025062052 - Improper locking in Linux kernel media rc driver
Published: June 20, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-49937)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the mceusb_gen1_init() function in drivers/media/rc/mceusb.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/587f793c64d99d92be8ef01c4c69d885a3f2edb6
- https://git.kernel.org/stable/c/608e58a0f4617977178131f5f68a3fce1d3f5316
- https://git.kernel.org/stable/c/75913c562f5ba4cf397d835c63f443879167c6f6
- https://git.kernel.org/stable/c/d69c738ac9310b56e84c51c8f09fc018a8291bc6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.8