SB20250226701 - Resource management error in Linux kernel media i2c driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-49509)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the max9286_poc_enable(), max9286_init(), max9286_probe() and max9286_remove() functions in drivers/media/i2c/max9286.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/365ab7ebc24eebb42b9e020aeb440d51af8960cd
- https://git.kernel.org/stable/c/579c77595dbbdfe4f2edf335899f86ac51eca4e9
- https://git.kernel.org/stable/c/9dd783274c89c21a038d967b52a858a297e767f8
- https://git.kernel.org/stable/c/a4ec75df70575cdf33d9638c7844e729bfe6ce24
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.46