PT-2022-17916 · Unknown+3 · V4L2Loopback+3
Published
2022-08-04
·
Updated
2024-04-08
·
CVE-2022-2652
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
v4l2loopback (affected versions not specified)
Description
The issue allows for potential kernel stack memory leakage due to improperly crafted format strings in the card label. Additionally, there is a possibility of a Denial of Service (DoS) because the v4l2loopback kernel module may crash when providing the card label on request, especially when many %s modifiers are used in a row.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Suse
V4L2Loopback