CVE-2024-24864

dvb: Race condition can lead to null pointer dereference in dvbdmx_write()

References

Notes

 bwh> I think this is a data race involving the dvb_demux::frontend
 bwh> field, and have added a link to an (incomplete) patch for this.
 bwh> I think the mutex needs to be taken earlier in both dvbdmx_write()
 bwh> and dvbdmx_connect_frontend().  Contrary to the information at
 bwh> cve.org, this is still unfixed as of 6.13-rc4.

Bugs

Status

Branch Status
upstream needed
6.18-upstream-stable
6.17-upstream-stable
6.12-upstream-stable
6.6-upstream-stable
6.1-upstream-stable needed
5.10-upstream-stable needed
4.19-upstream-stable needed
sid needed
6.12-trixie-security needed
6.1-bookworm-security needed
5.10-bullseye-security needed
4.19-buster-security needed