PT-2024-34008 · Linux+3 · Linux Kernel+3

Johan Hovold

·

Published

2024-07-29

·

Updated

2025-04-01

·

CVE-2024-50175

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the Linux kernel, specifically the media: qcom: camss component. A vulnerability has been resolved by removing the use count guard in stop streaming. The use count check was introduced to handle multiple concurrent Raw Data Interfaces (RDIs) driven by different virtual channels (VCs) on the CSIPHY input driving the video pipeline. However, this is an invalid use of use count, as it pertains to the number of times a video entity has been opened by user-space, not the number of active streams. If use count and stream-on count don't agree, then stop streaming() will break, which has become apparent when using CAMSS with libcamera's released softisp 0.3. The use of use count like this is a bit hacky and breaks regular usage of CAMSS for a single stream case. Stopping qcam results in an error and cannot be started again, with attempts to do so failing with -EBUSY.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07913
CVE-2024-50175
OESA-2025-1097
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7301-1
USN-7303-1
USN-7303-2
USN-7303-3
USN-7304-1
USN-7311-1
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1

Affected Products

Linuxmint
Linux Kernel
Suse
Ubuntu