ZeroHour

CVE-2022-2652

PoC
CVSS 3.1
6.0 medium
EPSS
<1%p26
Published
()
Modified
Description

Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row).

Vendors
v4l2loopback project
Products
v4l2loopback
Weakness
CWE-134
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.