SB20250619200 - Out-of-bounds read in Linux kernel nxp imx-jpeg driver
Published: June 19, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2022-50182)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the mxc_jpeg_config_enc_desc(), mxc_jpeg_source_change(), mxc_jpeg_queue_setup(), mxc_jpeg_parse(), mxc_jpeg_try_fmt() and mxc_jpeg_s_fmt() functions in drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/447795ffb17cd60bb544e0abfc9399e180a14a2f
- https://git.kernel.org/stable/c/73d1836ed7911953182b787745cb8c5857a2661c
- https://git.kernel.org/stable/c/9ae2d729de6350c53a06c57782751d84eb2c08d9
- https://git.kernel.org/stable/c/9e7aa76cdb02923ee23a0ddd48f38bdc3512f92b
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.61
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.18
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0