Bug#827340: linux: CVE-2010-5321 memory leak in videobuf on multiple calls to mmap()

2016-06-17 Thread Petter Reinholdtsen
Control: forwarded -1 https://bugzilla.kernel.org/show_bug.cgi?id=120571 I got some more information on the #v4l IRC channel and decided to report the issue upstream while I was at it. which driver are you using ? I guess uvcvideo based on the lsmod output. uvcvideo uses videobuf2 I quickly

Bug#827340: linux: CVE-2010-5321 memory leak in videobuf on multiple calls to mmap()

2016-06-17 Thread Petter Reinholdtsen
Control: found -1 4.6.2-1 [Petter Reinholdtsen] > If I understand the issue correctly, a user with access to /dev/video > can cause the kernel to leak memory and eventually run out of memory by > doing repeated calls to mmap(). In other words, users with video group > membership can bring down

Bug#827340: linux: CVE-2010-5321 memory leak in videobuf on multiple calls to mmap()

2016-06-15 Thread Petter Reinholdtsen
Package: src:linux Version: 3.2.78-1 Severity: minor Tags: security In 2010 an issue with the linux kernel implementation of v4l was discovered and reported to RedHat as https://bugzilla.redhat.com/show_bug.cgi?id=620629 >. It was assigned a CVE last year in