CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's synaptics-rmi4 driver, where changing the input type during an active video stream can lead to a heap buffer overflow due to mismatched buffer sizes. This could potentially allow an attacker to exploit the overflow, leading to arbitrary code execution or system crashes. Organizations utilizing affected Linux systems, particularly those relying on video input functionalities, should prioritize addressing this issue to mitigate potential security risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - block s_input when F54 queue is busy Changing the input (diagnostic report type) mid-stream changes the report size. Since V4L2 buffers are allocated based on the size at stream start, changing the input while streaming could lead to a heap buffer overflow if the new size is larger than the allocated buffers. Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue is busy (streaming).