Linux Kernel Memory Leak Vulnerability in Venus Video Decoder

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's Venus video decoder component. The issue arises in the 'venus_helper_alloc_dpb_bufs()' function, where an error in the ID allocation process can lead to an early return without releasing previously allocated buffers. This flaw has been addressed by moving the buffer deallocation from the error-checking phase of the DMA allocation to a common failure path, ensuring that all allocations are properly released in case of an error.

Impact

Exploitation of this vulnerability could lead to a memory leak, where allocated memory is not properly released, potentially causing increased memory usage and degradation of system performance over time.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.