media: v4l2-mem2mem: add lock to protect parameter num_rdy

Summary

CVECVE-2023-53519
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-10-01 12:15:56 UTC
Updated2026-04-06 13:04:59 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: add lock to protect parameter num_rdy Getting below error when using KCSAN to check the driver. Adding lock to protect parameter num_rdy when getting the value with function: v4l2_m2m_num_src_bufs_ready/v4l2_m2m_num_dst_bufs_ready. kworker/u16:3: [name:report&]BUG: KCSAN: data-race in v4l2_m2m_buf_queue kworker/u16:3: [name:report&] kworker/u16:3: [name:report&]read-write to 0xffffff8105f35b94 of 1 bytes by task 20865 on cpu 7: kworker/u16:3:  v4l2_m2m_buf_queue+0xd8/0x10c

Risk And Classification

Primary CVSS: v3.1 5.5 MEDIUM from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: CWE-667

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 690dd4780b3f4d755e4e7883e8c3d1b5052f6bf2 git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 7fc7f87725805197388ba749a1801df33000fa50 git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 ef009fe2010ea2a3a7045ecb72729cf366e0967b git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 e52de26cb37459b16213438a2c82feb155dd3bbd git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 1676748aa29099fc0abd71e0fb092e76e835f25c git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 c71aa5f1cf961264690f2560503ea396b6e3c680 git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 e01ea1c4191ee08440b5f86db98dff695e9cedf9 git Not specified
CNA Linux Linux affected 908a0d7c588ef87e5cf0a26805e6002a78ac9d13 56b5c3e67b0f9af3f45cf393be048ee8d8a92694 git Not specified
CNA Linux Linux affected 2.6.39 Not specified
CNA Linux Linux unaffected 2.6.39 semver Not specified
CNA Linux Linux unaffected 4.14.324 4.14.* semver Not specified
CNA Linux Linux unaffected 4.19.293 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.255 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.192 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.128 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.47 6.1.* semver Not specified
CNA Linux Linux unaffected 6.4.12 6.4.* semver Not specified
CNA Linux Linux unaffected 6.5 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/690dd4780b3f4d755e4e7883e8c3d1b5052f6bf2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/e52de26cb37459b16213438a2c82feb155dd3bbd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/7fc7f87725805197388ba749a1801df33000fa50 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/56b5c3e67b0f9af3f45cf393be048ee8d8a92694 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/1676748aa29099fc0abd71e0fb092e76e835f25c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/e01ea1c4191ee08440b5f86db98dff695e9cedf9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/c71aa5f1cf961264690f2560503ea396b6e3c680 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/ef009fe2010ea2a3a7045ecb72729cf366e0967b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report