Back

LOW

kernel: memory leak in drivers/media/cec/core/cec-api.c

Published Sep 18, 2023

Description

An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users, because of directly assigning log_addrs with a hole in the struct.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is to skip loading the affected module HDMI Consumer Electronics Control framework driver "cec" onto the system until we have a fix available. This can be done by a blacklist mechanism, which will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

Metrics

Weaknesses (0)

No CWE recorded.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 18, 2023
Updated Sep 25, 2024
Reserved Sep 18, 2023
CISA Vulnrichment
Updated Sep 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 19, 2023