CVE-2023-22656

NameCVE-2023-22656
DescriptionOut-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1082866, 1082867

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
intel-mediasdk (PTS)bullseye21.1.0-1vulnerable
bookworm22.5.4-1vulnerable
onevpl-intel-gpu (PTS)bookworm22.6.4-1vulnerable
sid, trixie24.3.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
intel-mediasdksourcebullseye(unfixed)end-of-life
intel-mediasdksource(unstable)(unfixed)1082866
onevpl-intel-gpusource(unstable)24.3.3-11082867

Notes

[bookworm] - intel-mediasdk <ignored> (No specific details published, development stalled and scheduled for removal from Debian)
[bullseye] - intel-mediasdk <end-of-life> (EOL in bullseye LTS)
[bookworm] - onevpl-intel-gpu <ignored> (Minor issue)
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html

Search for package or bug name: Reporting problems