-
CVE-2026-68217
- EPSS 0.22%
- Veröffentlicht 10.08.2026 12:00:36
- Zuletzt bearbeitet 19.08.2026 17:20:37
- Erkennungen
media: pwc: Drain fill_buf on start_streaming() failure
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Drain fill_buf on start_streaming() failure
pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:
start_streaming()
pwc_isoc_init()
usb_submit_urb(urbs[0], GFP_KERNEL)
pwc_isoc_handler(urbs[0])
pdev->fill_buf =
pwc_get_next_fill_buf(pdev)
usb_submit_urb(urbs[i>0], ..) -> fails
pwc_isoc_cleanup(pdev) /* kills URBs */
return ret;
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).
stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.
Issue identified by automated review of the INV-003 series at
https://sashiko.dev/Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
97f3c15957ec7e6d249f05407ad947c0644df24d
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
a4afffd148991a826e8995362fb10cf8705c1130
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
eabe9a59640698137d7382d5b549e95dc37f7565
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
a56e7641e09bd80b976e944ae759109b86fd5b38
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
acc789b2173070638cad89c2b61d33ed338be0dd
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
9afd605dcd96c7a45f338eded1de16679b30e1df
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
5d4812668b03f823b5044789d6aa77fe56b42587
Status
affected
Version
885fe18f5542fe283a17f70583383c6cadcba1c3
Version <
906e410dcffbbd99fb4081abab817a830033aa28
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.1
Status
affected
Version
0
Version <
3.1
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.148
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.127 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38
https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd
https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df
https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587
https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28
https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d
https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130
https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565