In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add 0 size check to mtk_drm_gem_obj Add a check to mtk_drm_gem_init if we attempt to allocate a GEM object of 0 bytes. Currently, no such check exists and the kernel will panic if a userspace application attempts to allocate a 0x0 GBM buffer. Tested by attempting to allocate a 0x0 GBM buffer on an MT8188 and verifying that we now return EINVAL.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | Firmware version 03.02.02(14) |
| Linux | Linux | 3.16.7S |
| Linux | Linux | Snapdragon 870 5G Mobile Platform (SM8250-AC) |
| Linux | Linux | WSA8835 |