The Linux kernel through 5.3.13 has a start_offset+size...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 4, 2023
Description
Published by the National Vulnerability Database
Nov 25, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 4, 2023
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
References