Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved: media: amphion: Fix race between m2m job_abort and device_run Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context. Race sequence: v4l2_m2m_try_run(): v4l2_m2m_ctx_release(): lock/unlock v4l2_m2m_cancel_job() job_abort() v4l2_m2m_job_finish() kfree(m2m_ctx) <- frees ctx device_run() <- use-after-free crash at 0x538 Crash trace: Unable to handle kernel read from unreadable memory at virtual address 0000000000000538 v4l2_m2m_try_run+0x78/0x138 v4l2_m2m_device_run_work+0x14/0x20 The amphion vpu driver does not rely on the m2m framework’s device_run callback to perform encode/decode operations. Fix the race by preventing m2m framework job scheduling entirely:
- Add job_ready callback returning 0 (no jobs ready for m2m framework)
- Remove job_abort callback to avoid the race condition A flaw was found in the Linux kernel, specifically within the amphion video processing unit (VPU) driver. A race condition, a situation where multiple operations occur in an unpredictable order, exists in the Video for Linux 2 (V4L2) media-to-memory (m2m) framework. This vulnerability allows a local attacker to exploit a timing issue, leading to a use-after-free error that can cause a kernel panic and result in a denial of service for the system.
Details
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 12 | Planned | — |
| Debian 13 | Will Not Fix |
6 kernels
|
| Ubuntu 24.04 | Planned | — |