In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: fix a bug of accessing array out of bounds When error occurs in parsing jpeg, the slot isn't acquired yet, it may be the default value MXC_MAX_SLOTS. If the driver access the slot using the incorrect slot number, it will access array out of bounds. The result is the driver will change num_domains, which follows slot_data in struct mxc_jpeg_dev. Then the driver won't detach the pm domain at rmmod, which will lead to kernel panic when trying to insmod again.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 8.1 |
| Linux | Linux | n/a |
| Linux | Linux | 10 Version 1709 for 32-bit Systems |
| Linux | Linux | 10 Version 1803 for x64-based Systems |