CVE-2024-43831

MEDIUM

Linux Kernel 4.10-6.1.130, 6.2.0-6.6.43, 6.7.0-6.10.2 - Denial of Service in MediaTek Vcodec Decoder VSI Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Handle invalid decoder vsi Handle an invalid decoder vsi in vpu_dec_init to ensure the decoder vsi is valid for future use.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (14)
linux/Kernel 4.10.0 - 6.1.131linux
linux/Kernel 6.2.0 - 6.6.44linux
linux/Kernel 6.7.0 - 6.10.3linux
Linux/Linux < 4.10
Linux/Linux 4.10
Linux/Linux 590577a4e5257ac3ed72999a94666ad6ba8f24bc - 1c109f23b271a02b9bb195c173fab41e3285a8db
Linux/Linux 590577a4e5257ac3ed72999a94666ad6ba8f24bc - 59d438f8e02ca641c58d77e1feffa000ff809e9f
Linux/Linux 590577a4e5257ac3ed72999a94666ad6ba8f24bc - cdf05ae76198c513836bde4eb55f099c44773280
Linux/Linux 590577a4e5257ac3ed72999a94666ad6ba8f24bc - dbd3e4adb98e50ede74f00b3fa956fa29ef95e6c
Linux/Linux 6.1.131 - 6.1.*
... and 4 more
Published Aug 17, 2024
Tracked Since Feb 18, 2026