CVE-2022-49247

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49247
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49247.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49247
Related
Published
2025-02-26T07:01:01Z
Modified
2025-02-26T18:58:40.222434Z
Downstream
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

media: stk1160: If start stream fails, return buffers with VB2BUFSTATE_QUEUED

If the callback 'startstreaming' fails, then all queued buffers in the driver should be returned with state 'VB2BUFSTATEQUEUED'. Currently, they are returned with 'VB2BUFSTATE_ERROR' which is wrong. Fix this. This also fixes the warning:

[ 65.583633] WARNING: CPU: 5 PID: 593 at drivers/media/common/videobuf2/videobuf2-core.c:1612 vb2startstreaming+0xd4/0x160 [videobuf2common] [ 65.585027] Modules linked in: sndusbaudio sndhwdep sndusbmidilib sndrawmidi sndsochdmicodec dwhdmii2saudio saa7115 stk1160 videobuf2vmalloc videobuf2memops videobuf2v4l2 videobuf2common videodev mc crct10difce panfrost sndsocsimplecard sndsocaudiographcard sndsocspdiftx sndsocsimplecardutils gpusched phyrockchippcie sndsocrockchipi2s rockchipdrm analogixdp dwmipidsi dwhdmi cec drmkmshelper drm rtcrk808 rockchipsaradc industrialiotriggeredbuffer kfifobuf rockchipthermal pcierockchiphost iptables xtables ipv6 [ 65.589383] CPU: 5 PID: 593 Comm: v4l2src0:src Tainted: G W 5.16.0-rc4-62408-g32447129cb30-dirty #14 [ 65.590293] Hardware name: Radxa ROCK Pi 4B (DT) [ 65.590696] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 65.591304] pc : vb2startstreaming+0xd4/0x160 [videobuf2common] [ 65.591850] lr : vb2startstreaming+0x6c/0x160 [videobuf2common] [ 65.592395] sp : ffff800012bc3ad0 [ 65.592685] x29: ffff800012bc3ad0 x28: 0000000000000000 x27: ffff800012bc3cd8 [ 65.593312] x26: 0000000000000000 x25: ffff00000d8a7800 x24: 0000000040045612 [ 65.593938] x23: ffff800011323000 x22: ffff800012bc3cd8 x21: ffff00000908a8b0 [ 65.594562] x20: ffff00000908a8c8 x19: 00000000fffffff4 x18: ffffffffffffffff [ 65.595188] x17: 000000040044ffff x16: 00400034b5503510 x15: ffff800011323f78 [ 65.595813] x14: ffff000013163886 x13: ffff000013163885 x12: 00000000000002ce [ 65.596439] x11: 0000000000000028 x10: 0000000000000001 x9 : 0000000000000228 [ 65.597064] x8 : 0101010101010101 x7 : 7f7f7f7f7f7f7f7f x6 : fefefeff726c5e78 [ 65.597690] x5 : ffff800012bc3990 x4 : 0000000000000000 x3 : ffff000009a34880 [ 65.598315] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000007cd99f0 [ 65.598940] Call trace: [ 65.599155] vb2startstreaming+0xd4/0x160 [videobuf2common] [ 65.599672] vb2corestreamon+0x17c/0x1a8 [videobuf2common] [ 65.600179] vb2streamon+0x54/0x88 [videobuf2v4l2] [ 65.600619] vb2ioctlstreamon+0x54/0x60 [videobuf2v4l2] [ 65.601103] v4lstreamon+0x3c/0x50 [videodev] [ 65.601521] _videodoioctl+0x1a4/0x428 [videodev] [ 65.601977] videousercopy+0x320/0x828 [videodev] [ 65.602419] videoioctl2+0x3c/0x58 [videodev] [ 65.602830] v4l2ioctl+0x60/0x90 [videodev] [ 65.603227] _arm64sysioctl+0xa8/0xe0 [ 65.603576] invokesyscall+0x54/0x118 [ 65.603911] el0svccommon.constprop.3+0x84/0x100 [ 65.604332] doel0svc+0x34/0xa0 [ 65.604625] el0svc+0x1c/0x50 [ 65.604897] el0t64synchandler+0x88/0xb0 [ 65.605264] el0t64sync+0x16c/0x170 [ 65.605587] ---[ end trace 578e0ba07742170d ]---

References

Affected packages

Debian:11 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.113-1

Affected versions

5.*

5.10.46-4
5.10.46-5
5.10.70-1~bpo10+1
5.10.70-1
5.10.84-1
5.10.92-1~bpo10+1
5.10.92-1
5.10.92-2
5.10.103-1~bpo10+1
5.10.103-1
5.10.106-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.17.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.17.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}