CVE-2026-89741

Summary

In the Linux kernel, the following vulnerability has been resolved:

Revert "media: v4l2-dev: fix error handling in __video_register_device()"

This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a.

The intentions of that patch were good, but it doesn't work.

The idea is that if device_register fails, you have to do a put_device to let the ref counter release resources.

However, the V4L2 API says that if video_register_device() fails, then you have to call video_device_release(), which kfree()s the video_device struct.

But the put_device() will already have freed the struct, so you end up in a double-free scenario.

There is not really a good way of fixing this without breaking video_register_device() into two parts, one that initializes everything, and one that does the actual device_register, and then converting all V4L2 drivers to this new model.

That is a massive job, and it is very unlikely that device_register will fail.

So rather than ending up in a double-free scenario, just revert this patch, and in that case we'll have a small memory leak. Which is a lot more robust.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux2429bb9fad88c8fa84c4956b0a21cf5afe5e92b7 < 712ca1cf756de2557a116e0df55791bac0c9f99eaffected
LinuxLinux2a934fdb01db6458288fc9386d3d8ceba6dd551a < aad08b5f67d2a8116e1a00bce2611c1513b10bceaffected
LinuxLinux2a934fdb01db6458288fc9386d3d8ceba6dd551a < ce792b94e03882108019ba996c1a7c4d4e09be2caffected
LinuxLinux2a934fdb01db6458288fc9386d3d8ceba6dd551a < e7600f5cee5de14065f950807931d6e6d40fb2d7affected
LinuxLinuxee141706e701356dda41c6fed9ee18bf427c28e3affected
LinuxLinuxe5c8e62ae551e0ad2e15412aa0c57c2856d59677affected
LinuxLinux8b451a9a46f2bfc510e6d5c2492df91647586184affected
LinuxLinuxb6be1f5633eae200af2527e9eeb7f51be5739b0faffected
LinuxLinuxae7b143e05b36fc69d6571751855946cc45064c6affected
LinuxLinux4451412739ed33a49b34624299394ee575116d0caffected
LinuxLinux6.12.35 < 6.12.109affected
LinuxLinux5.4.295 < 5.5affected
LinuxLinux5.10.239 < 5.11affected
LinuxLinux5.15.186 < 5.16affected
LinuxLinux6.1.142 < 6.2affected
LinuxLinux6.6.95 < 6.7affected
LinuxLinux6.15.4 < 6.16affected
LinuxLinux6.16affected
LinuxLinux0 < 6.16unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References