CVE-2023-54284

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/12/2025
Last modified:
30/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: av7110: prevent underflow in write_ts_to_decoder()<br /> <br /> The buf[4] value comes from the user via ts_play(). It is a value in<br /> the u8 range. The final length we pass to av7110_ipack_instant_repack()<br /> is "len - (buf[4] + 1) - 4" so add a check to ensure that the length is<br /> not negative. It&amp;#39;s not clear that passing a negative len value does<br /> anything bad necessarily, but it&amp;#39;s not best practice.<br /> <br /> With the new bounds checking the "if (!len)" condition is no longer<br /> possible or required so remove that.

Impact