Bug 3330 - [ANCK 5.10 Dev] Bugfix for CVE-2022-45884
Summary: [ANCK 5.10 Dev] Bugfix for CVE-2022-45884
Status: RESOLVED INVALID
Alias: None
Product: ANCK 5.10 Dev
Classification: ANCK
Component: general/others (show other bugs) general/others
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: maqiao
QA Contact: shuming
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2022-12-01 14:47 UTC by 小龙
Modified: 2023-09-07 10:06 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2022-12-01 14:47:09 UTC
Description:
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.

Broken commit info:

Bugfix commit info:
Comment 1 maqiao alibaba_cloud_group 2022-12-02 13:28:18 UTC
same as https://bugzilla.openanolis.cn/show_bug.cgi?id=3328
Comment 2 maqiao alibaba_cloud_group 2023-09-07 10:06:12 UTC
CONFIG_MEDIA_DIGITAL_TV_SUPPORT is disabled, this cve is not affected.
see: https://bugzilla.openanolis.cn/show_bug.cgi?id=6274