Description
Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row).
Scores
CVSS v3
6.0
EPSS
0.0005
EPSS Percentile
16.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-134
Status
published
Products (1)
v4l2loopback_project/v4l2loopback
< 0.12.6
Published
Aug 04, 2022
Tracked Since
Feb 18, 2026