-
CVE-2026-89900
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:32:00
- Zuletzt bearbeitet 16.09.2026 11:16:58
- Erkennungen
media: cec: core: Fix kmemleak due to missed rc_free_device() call
In the Linux kernel, the following vulnerability has been resolved:
media: cec: core: Fix kmemleak due to missed rc_free_device() call
The commit dccc0c3ddf8f ("media: rc: fix race between unregister and
urb/irq callbacks") removed the implicit call to rc_free_device() from
rc_unregister_device(). However, the commit missed to remove the NULL
assignment of adap->rc that is now causing rc_free_device() to never be
called on an allocated rc device.
kmemleak reports following after e.g. dw-hdmi unbind:
unreferenced object 0xffff00010ac10000 (size 4096):
comm "kworker/u16:1", pid 39, jiffies 4294897739
hex dump (first 32 bytes):
20 23 4b 0a 01 00 ff ff 08 00 c1 0a 01 00 ff ff #K.............
08 00 c1 0a 01 00 ff ff 00 00 00 00 00 00 00 00 ................
backtrace (crc e11baccc):
kmemleak_alloc+0x38/0x44
__kmalloc_cache_noprof+0x4a8/0x5e0
rc_allocate_device+0x48/0x2a0
cec_allocate_adapter+0x3ac/0x800
dw_hdmi_cec_probe+0x264/0x634
platform_probe+0xc0/0x188
really_probe+0x4a4/0x8e0
__driver_probe_device+0x2f8/0x440
driver_probe_device+0x60/0x160
__device_attach_driver+0x1a0/0x2a0
bus_for_each_drv+0x100/0x1a0
__device_attach+0x174/0x350
device_initial_probe+0x90/0xb0
bus_probe_device+0x4c/0x120
device_add+0xdec/0x116c
platform_device_add+0x354/0x598
Remove the assignment of adap->rc to NULL to let cec_delete_adapter()
free the allocated rc device after last user of the cec device exits to
fix the kmemleak.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
a7becb58f6b8a3a3efe5d3acfd52e2c107de6772
Version <
954ee95a03b4d31d4505591bfaba02c24b75776b
Status
affected
Version
75977f5f5c4974c72bbedefbf09ad33ebbaa36f1
Version <
f28a8e1ba4d67a18e4662e5acefd5a4389322366
Status
affected
Version
e250b672d40a9e0d97a8895cbb301248bea0fce6
Version <
695063fc57574dd117b1bc750ca189cf03a2caad
Status
affected
Version
dccc0c3ddf8f16071736f98a7d6dd46a2d43e037
Version <
cca2407794795cecff7f8e5f5a79f4ef6b1d6f6c
Status
affected
Version
dccc0c3ddf8f16071736f98a7d6dd46a2d43e037
Version <
a24ba0653f7154e671dc8d2bf64682ab2d042792
Status
affected
Version
6.6.143
Version <
6.6.157
Status
affected
Version
6.12.93
Version <
6.12.110
Status
affected
Version
6.18.35
Version <
6.18.51
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.1
Status
affected
Version
0
Version <
7.1
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.102 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/954ee95a03b4d31d4505591bfaba02c24b75776b
https://git.kernel.org/stable/c/f28a8e1ba4d67a18e4662e5acefd5a4389322366
https://git.kernel.org/stable/c/695063fc57574dd117b1bc750ca189cf03a2caad
https://git.kernel.org/stable/c/cca2407794795cecff7f8e5f5a79f4ef6b1d6f6c
https://git.kernel.org/stable/c/a24ba0653f7154e671dc8d2bf64682ab2d042792