CVE-2010-5321
low-risk
Published 2017-04-24
Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761. NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.
Do I need to act?
-
0.13% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.3/10
Medium
PHYSICAL
/ LOW complexity
Affected Products (1)
Affected Vendors
References (10)
Not Applicable
http://linuxtv.org/irc/v4l/index.php?date=2010-07-29
Issue Tracking
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827340
Issue Tracking
https://bugzilla.kernel.org/show_bug.cgi?id=120571
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=620629
Not Applicable
http://linuxtv.org/irc/v4l/index.php?date=2010-07-29
Issue Tracking
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827340
Issue Tracking
https://bugzilla.kernel.org/show_bug.cgi?id=120571
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=620629
21
/ 100
low-risk
Severity
15/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
5/34 · Minimal