-

CVE-2026-89901

media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref

In the Linux kernel, the following vulnerability has been resolved:

media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref

airspy_disconnect() clears s->udev under v4l2_lock, but
airspy_stop_streaming() unconditionally calls airspy_ctrl_msg() and
airspy_free_stream_bufs() afterwards. If a streaming user closes the
device after disconnect, stop_streaming() runs and dereferences the
NULL s->udev:

  airspy_stop_streaming()
    airspy_ctrl_msg(s, CMD_RECEIVER_MODE, 0, 0, NULL, 0)
      usb_sndctrlpipe(s->udev, 0)         /* NULL deref */
    airspy_free_stream_bufs(s)
      usb_free_coherent(s->udev, ...)     /* NULL deref */

The airspy driver uses vb2_fop_release() in its file_operations, so
replace video_unregister_device(&s->vdev) with
vb2_video_unregister_device(&s->vdev) and move it before clearing
s->udev. vb2_video_unregister_device() releases the vb2 queue, which
synchronously runs airspy_stop_streaming() if streaming is active, so
the URBs, coherent DMA stream buffers and the hardware stop control
message all execute while s->udev is still valid.

vb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock)
internally, and stop_streaming() locks v4l2_lock, so the previous outer
mutex_lock(&s->vb_queue_lock) / mutex_lock(&s->v4l2_lock) pair around
the unregister sequence would self-deadlock and has been removed. A
short v4l2_lock critical section around s->udev = NULL remains so any
ioctl path that still holds the file descriptor sees coherent state.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < c9081e2655188d2d134a741aec837dc70439d505
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < 75089cea32e5055773bd13116236d08fdc98678a
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < 155d0378ae0d6305cc4840583a6b42d2d0595bff
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < 6e4ea90fdc6608cd5fac342e146ab6ae15d430bc
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < a9a8c37ddda9fa3687b142be9098e1c37b8faf35
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < 297fee023f46d771a844520675692ea089d80d9d
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < c6749ac8f59cc80eb1b2d52f167fdf13e12655cc
Status affected
Version 634fe5033951b80ef4b98d8f047cb1083d29170d
Version < 2f378dc45e685fc825d2dd08e7864666d6fcc009
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c9081e2655188d2d134a741aec837dc70439d505
https://git.kernel.org/stable/c/75089cea32e5055773bd13116236d08fdc98678a
https://git.kernel.org/stable/c/155d0378ae0d6305cc4840583a6b42d2d0595bff
https://git.kernel.org/stable/c/6e4ea90fdc6608cd5fac342e146ab6ae15d430bc
https://git.kernel.org/stable/c/a9a8c37ddda9fa3687b142be9098e1c37b8faf35
https://git.kernel.org/stable/c/297fee023f46d771a844520675692ea089d80d9d
https://git.kernel.org/stable/c/c6749ac8f59cc80eb1b2d52f167fdf13e12655cc
https://git.kernel.org/stable/c/2f378dc45e685fc825d2dd08e7864666d6fcc009