#VU99204 Input validation error in Linux kernel - CVE-2024-50056
Published: October 22, 2024 / Updated: May 12, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the find_format_by_pix(), uvc_v4l2_try_format() and uvc_v4l2_enum_format() functions in drivers/usb/gadget/function/uvc_v4l2.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/cedeb36c3ff4acd0f3d09918dfd8ed1df05efdd6
- https://git.kernel.org/stable/c/a7bb96b18864225a694e3887ac2733159489e4b0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.133
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.86