CVE-2023-52764

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-52764
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52764.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52764
Downstream
Related
Published
2024-05-21T15:30:49.032Z
Modified
2025-11-28T02:34:46.154674Z
Summary
media: gspca: cpia1: shift-out-of-bounds in set_flicker
Details

In the Linux kernel, the following vulnerability has been resolved:

media: gspca: cpia1: shift-out-of-bounds in set_flicker

Syzkaller reported the following issue: UBSAN: shift-out-of-bounds in drivers/media/usb/gspca/cpia1.c:1031:27 shift exponent 245 is too large for 32-bit type 'int'

When the value of the variable "sd->params.exposure.gain" exceeds the number of bits in an integer, a shift-out-of-bounds error is reported. It is triggered because the variable "currentexp" cannot be left-shifted by more than the number of bits in an integer. In order to avoid invalid range during left-shift, the conditional expression is added.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52764.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
69bba62600bd91d6b7c1e8ca181faf8ac64f7060
Fixed
2eee8edfff90e22980a6b22079d238c3c9d323bb
Fixed
8f83c85ee88225319c52680792320c02158c2a9b
Fixed
c6b6b8692218da73b33b310d7c1df90f115bdd9a
Fixed
09cd8b561aa9796903710a1046957f2b112c8f26
Fixed
a647f27a7426d2fe1b40da7c8fa2b81354a51177
Fixed
93bddd6529f187f510eec759f37d0569243c9809
Fixed
e2d7149b913d14352c82624e723ce1c211ca06d3
Fixed
099be1822d1f095433f4b08af9cc9d6308ec1953

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.331
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.300
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.262
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.202
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.140
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.64
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.13
Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.3