-

CVE-2026-89896

media: cedrus: fix memory leak in cedrus_init_ctrls()

In the Linux kernel, the following vulnerability has been resolved:

media: cedrus: fix memory leak in cedrus_init_ctrls()

In cedrus_init_ctrls(), the V4L2 control handler is initialized before
allocating memory for ctx->ctrls. If this allocation fails, the function
returns -ENOMEM without freeing the previously allocated handler
resources, leading to a memory leak.

Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation
failure path.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an
Allwinner SoC or board with a Cedrus VPU available to test with, no
runtime testing was able to be performed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 6fabacc3b79a528450aef4c32464da2ec681049e
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 729a1ffab968b3c493f61d1cd683f5bafec500ea
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < ce5693b6e3a693fcdc3800af309363f6250104c8
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 22441be29ec27c693f40c1ef499093275ef529d1
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 79fd0b0161506fc9507bf7a6fe4c975a857a5be8
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < f78cf36cabf911da348ea80e4e9f430d74f6905c
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 81aa608ac3a56cdd4aab0bd12442ed529a24ba31
Status affected
Version 50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Version < 9df2fbe563194da1967a5db083442186c1323efe
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.20
Status affected
Version 0
Version < 4.20
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6fabacc3b79a528450aef4c32464da2ec681049e
https://git.kernel.org/stable/c/729a1ffab968b3c493f61d1cd683f5bafec500ea
https://git.kernel.org/stable/c/ce5693b6e3a693fcdc3800af309363f6250104c8
https://git.kernel.org/stable/c/22441be29ec27c693f40c1ef499093275ef529d1
https://git.kernel.org/stable/c/79fd0b0161506fc9507bf7a6fe4c975a857a5be8
https://git.kernel.org/stable/c/f78cf36cabf911da348ea80e4e9f430d74f6905c
https://git.kernel.org/stable/c/81aa608ac3a56cdd4aab0bd12442ed529a24ba31
https://git.kernel.org/stable/c/9df2fbe563194da1967a5db083442186c1323efe