Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-54284

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
30/12/2025
Última modificación:
30/12/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: av7110: prevent underflow in write_ts_to_decoder()<br /> <br /> The buf[4] value comes from the user via ts_play(). It is a value in<br /> the u8 range. The final length we pass to av7110_ipack_instant_repack()<br /> is "len - (buf[4] + 1) - 4" so add a check to ensure that the length is<br /> not negative. It&amp;#39;s not clear that passing a negative len value does<br /> anything bad necessarily, but it&amp;#39;s not best practice.<br /> <br /> With the new bounds checking the "if (!len)" condition is no longer<br /> possible or required so remove that.

Impacto