7.8
CVE-2026-89522
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:44:04
- Zuletzt bearbeitet 13.09.2026 07:17:14
- Erkennungen
media: staging/ipu7: fix async notifier UAF on probe error path
In the Linux kernel, the following vulnerability has been resolved: media: staging/ipu7: fix async notifier UAF on probe error path isys_register_devices() registers the V4L2 async notifier via isys_notifier_init(). If a subsequent probe step such as isys_fw_log_init() fails, isys_probe() jumps to the out_cleanup label which only calls isys_unregister_devices(). That helper tears down the video devices, subdevices, V4L2 device and media device, but never unregisters or cleans up the async notifier. As a result the notifier stays chained in the global notifier_list while the enclosing struct ipu7_isys is freed by devres, leading to list corruption and a use-after-free the next time the list is walked. The remove path already does the right thing by calling isys_notifier_cleanup() before isys_unregister_devices(). Mirror that on the probe error path so the notifier is unregistered and cleaned up before the device is torn down.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
a516d36bdc3d8373f904af57c95e76d6f921cf1c
Version <
2a8dd9fd12f3f6b21207cec8f50c92cd428e6b81
Status
affected
Version
a516d36bdc3d8373f904af57c95e76d6f921cf1c
Version <
323c411fb63122e8cef5b833032d69d59a838559
Status
affected
Version
a516d36bdc3d8373f904af57c95e76d6f921cf1c
Version <
d7f48aa7d60c65d3e6d5312c27f17d5525a245fb
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.17
Status
affected
Version
0
Version <
6.17
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/2a8dd9fd12f3f6b21207cec8f50c92cd428e6b81
https://git.kernel.org/stable/c/323c411fb63122e8cef5b833032d69d59a838559
https://git.kernel.org/stable/c/d7f48aa7d60c65d3e6d5312c27f17d5525a245fb