7.8

CVE-2026-89880

media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure

In the Linux kernel, the following vulnerability has been resolved:

media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure

rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(),
rtl2832_sdr_alloc_urbs() and rtl2832_sdr_submit_urbs() in sequence and
shares a single err: label that only unlocks the mutex and returns.
When alloc_urbs() succeeds but submit_urbs() fails, or when alloc_urbs()
itself returns -ENOMEM after alloc_stream_bufs() has already succeeded,
the URBs and/or the coherent DMA stream buffers stay allocated while
streaming reports failure to vb2. Two latent defects follow on the next
VIDIOC_STREAMON:

1) rtl2832_sdr_alloc_stream_bufs() unconditionally resets dev->buf_num
   to 0 and overwrites dev->buf_list[]/dev->dma_addr[], permanently
   leaking the coherent DMA memory allocated by the previous attempt.

2) rtl2832_sdr_alloc_urbs() never resets dev->urbs_initialized and only
   increments it. After a second successful pass urbs_initialized can
   exceed MAX_BULK_BUFS, so the subsequent rtl2832_sdr_free_urbs() walks
   from urbs_initialized - 1 down to 0 and reads past the end of
   dev->urb_list[], passing garbage pointers to usb_free_urb().

Mirror the teardown that stop_streaming() already performs: on the error
path call rtl2832_sdr_free_urbs() and rtl2832_sdr_free_stream_bufs()
before unlocking. Both helpers are idempotent (free_urbs kills and zeros
urbs_initialized; free_stream_bufs is gated on URB_BUF and clears the
buf_num counter), so partial-failure paths and the no-allocation paths
remain safe.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < f14a713a36a5c87568430e9770896f2a8f5bbbb7
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < c819dea3a433ae790b829443fdcc1715d1586560
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < 0337ab0759285076a3f9dcfcc40906e69ab519b3
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < c91e8ae2b39c6da81f26f2c9877d3fd33a4465ce
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < 8bcf11a239eac4e224ad856277de9a36c91b1711
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < 26a2a985bbeee3eaa6f80ff7de732161a171ec9f
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < ac02b2c56ccef0788cea9b86990a8f349a3fc6d8
Status affected
Version 771138920eafa399f68d3492c8a75dfeea23474b
Version < fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.15
Status affected
Version 0
Version < 3.15
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f14a713a36a5c87568430e9770896f2a8f5bbbb7
https://git.kernel.org/stable/c/c819dea3a433ae790b829443fdcc1715d1586560
https://git.kernel.org/stable/c/0337ab0759285076a3f9dcfcc40906e69ab519b3
https://git.kernel.org/stable/c/c91e8ae2b39c6da81f26f2c9877d3fd33a4465ce
https://git.kernel.org/stable/c/8bcf11a239eac4e224ad856277de9a36c91b1711
https://git.kernel.org/stable/c/26a2a985bbeee3eaa6f80ff7de732161a171ec9f
https://git.kernel.org/stable/c/ac02b2c56ccef0788cea9b86990a8f349a3fc6d8
https://git.kernel.org/stable/c/fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4