-

CVE-2026-68217

media: pwc: Drain fill_buf on start_streaming() failure

In the Linux kernel, the following vulnerability has been resolved:

media: pwc: Drain fill_buf on start_streaming() failure

pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:

  start_streaming()
    pwc_isoc_init()
      usb_submit_urb(urbs[0], GFP_KERNEL)
                                  pwc_isoc_handler(urbs[0])
                                    pdev->fill_buf =
                                      pwc_get_next_fill_buf(pdev)
      usb_submit_urb(urbs[i>0], ..)  -> fails
      pwc_isoc_cleanup(pdev)           /* kills URBs */
      return ret;
    pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)

pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).

stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < 97f3c15957ec7e6d249f05407ad947c0644df24d
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < a4afffd148991a826e8995362fb10cf8705c1130
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < eabe9a59640698137d7382d5b549e95dc37f7565
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < a56e7641e09bd80b976e944ae759109b86fd5b38
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < acc789b2173070638cad89c2b61d33ed338be0dd
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < 9afd605dcd96c7a45f338eded1de16679b30e1df
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < 5d4812668b03f823b5044789d6aa77fe56b42587
Status affected
Version 885fe18f5542fe283a17f70583383c6cadcba1c3
Version < 906e410dcffbbd99fb4081abab817a830033aa28
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.1
Status affected
Version 0
Version < 3.1
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.127
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38
https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd
https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df
https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587
https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28
https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d
https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130
https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565