CVE-2024-35920
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/05/2024
Last modified:
20/05/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
media: mediatek: vcodec: adding lock to protect decoder context list<br />
<br />
Add a lock for the ctx_list, to avoid accessing a NULL pointer<br />
within the &#39;vpu_dec_ipi_handler&#39; function when the ctx_list has<br />
been deleted due to an unexpected behavior on the SCP IP block.<br />
<br />
Hardware name: Google juniper sku16 board (DT)<br />
pstate: 20400005 (nzCv daif +PAN -UAO -TCO BTYPE=--)<br />
pc : vpu_dec_ipi_handler+0x58/0x1f8 [mtk_vcodec_dec]<br />
lr : scp_ipi_handler+0xd0/0x194 [mtk_scp]<br />
sp : ffffffc0131dbbd0<br />
x29: ffffffc0131dbbd0 x28: 0000000000000000<br />
x27: ffffff9bb277f348 x26: ffffff9bb242ad00<br />
x25: ffffffd2d440d3b8 x24: ffffffd2a13ff1d4<br />
x23: ffffff9bb7fe85a0 x22: ffffffc0133fbdb0<br />
x21: 0000000000000010 x20: ffffff9b050ea328<br />
x19: ffffffc0131dbc08 x18: 0000000000001000<br />
x17: 0000000000000000 x16: ffffffd2d461c6e0<br />
x15: 0000000000000242 x14: 000000000000018f<br />
x13: 000000000000004d x12: 0000000000000000<br />
x11: 0000000000000001 x10: fffffffffffffff0<br />
x9 : ffffff9bb6e793a8 x8 : 0000000000000000<br />
x7 : 0000000000000000 x6 : 000000000000003f<br />
x5 : 0000000000000040 x4 : fffffffffffffff0<br />
x3 : 0000000000000020 x2 : ffffff9bb6e79080<br />
x1 : 0000000000000010 x0 : ffffffc0131dbc08<br />
Call trace:<br />
vpu_dec_ipi_handler+0x58/0x1f8 [mtk_vcodec_dec (HASH:6c3f 2)]<br />
scp_ipi_handler+0xd0/0x194 [mtk_scp (HASH:7046 3)]<br />
mt8183_scp_irq_handler+0x44/0x88 [mtk_scp (HASH:7046 3)]<br />
scp_irq_handler+0x48/0x90 [mtk_scp (HASH:7046 3)]<br />
irq_thread_fn+0x38/0x94<br />
irq_thread+0x100/0x1c0<br />
kthread+0x140/0x1fc<br />
ret_from_fork+0x10/0x30<br />
Code: 54000088 f94ca50a eb14015f 54000060 (f9400108)<br />
---[ end trace ace43ce36cbd5c93 ]---<br />
Kernel panic - not syncing: Oops: Fatal exception<br />
SMP: stopping secondary CPUs<br />
Kernel Offset: 0x12c4000000 from 0xffffffc010000000<br />
PHYS_OFFSET: 0xffffffe580000000<br />
CPU features: 0x08240002,2188200c<br />
Memory Limit: none



