Back

HIGH

media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()

Published Sep 4, 2025

Description

The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes.

This can lead to an out-of-bounds read if the buffer has exactly 3 bytes.

Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().

Affected products

Remediation

Red Hat statement

A flaw was found in the Linux kernel UVC video driver where uvc_parse_format() could perform a one-byte out-of-bounds read when parsing a format descriptor if the buffer length was exactly three bytes. This can only cause an invalid read of uninitialized memory, leading at most to a local denial of service.

Red Hat mitigation

To mitigate this issue, prevent module uvcvideo from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

References (18)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 4, 2025
Updated May 12, 2026
Reserved Apr 16, 2025

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Sep 4, 2025
Bugzilla 2393159

ENISA EUVD

Assigner Linux
Published Sep 4, 2025
Updated May 12, 2026

GitHub

No data