CVE-2026-80650
In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: gc2235: fix UAF and memory leak
gc2235_probe() handles its error paths incorrectly.
If media_entity_pads_init() fails, gc2235_remove() is called, which tears down the subdev and frees dev, but then still falls through to atomisp_register_i2c_module(). This results in use-after-free.
If atomisp_register_i2c_module() fails, the media entity and control handler are left initialized and dev is leaked.
gc2235_remove() unconditionally calls media_entity_cleanup() and v4l2_ctrl_handler_free(), but these are not initialized at every error path in gc2235_probe().
Leer descripción completaMostrar menos
Replace gc2235_remove() calls in the probe error paths with explicit unwind labels that free only the resources initialized at each point of failure, in reverse order of initialization.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
- https://git.kernel.org/stable/c/628f763aee0047ff44974388d6f70f75a763026b
- https://git.kernel.org/stable/c/d57e67ea48e4d095052f2b14d8dd7593621f862f
- https://git.kernel.org/stable/c/f614bf0a64aa1cb7444d152a96798a6bf1d49e1f
- https://git.kernel.org/stable/c/fdbb8e55578b4ab647fa58827a9dd8730d7f4add
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80650",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a49d25364dfb9f8a64037488a39ab1f56c5fa419",
"lessThan": "51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654",
"versionType": "git"
},
{
"status": "affected",
"version": "ad85094b293e40e7a2f831b0311a389d952ebd5e",
"lessThan": "fdbb8e55578b4ab647fa58827a9dd8730d7f4add",
"versionType": "git"
},
{
"status": "affected",
"version": "ad85094b293e40e7a2f831b0311a389d952ebd5e",
"lessThan": "d57e67ea48e4d095052f2b14d8dd7593621f862f",
"versionType": "git"
},
{
"status": "affected",
"version": "ad85094b293e40e7a2f831b0311a389d952ebd5e",
"lessThan": "f614bf0a64aa1cb7444d152a96798a6bf1d49e1f",
"versionType": "git"
},
{
"status": "affected",
"version": "ad85094b293e40e7a2f831b0311a389d952ebd5e",
"lessThan": "628f763aee0047ff44974388d6f70f75a763026b",
"versionType": "git"
}
],
"programFiles": [
"drivers/staging/media/atomisp/i2c/atomisp-gc2235.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"status": "affected",
"version": "5.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.18",
"lessThan": "5.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/staging/media/atomisp/i2c/atomisp-gc2235.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:50.010",
"references": [
{
"url": "https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/628f763aee0047ff44974388d6f70f75a763026b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d57e67ea48e4d095052f2b14d8dd7593621f862f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f614bf0a64aa1cb7444d152a96798a6bf1d49e1f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fdbb8e55578b4ab647fa58827a9dd8730d7f4add",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: atomisp: gc2235: fix UAF and memory leak\n\ngc2235_probe() handles its error paths incorrectly.\n\nIf media_entity_pads_init() fails, gc2235_remove() is called, which\ntears down the subdev and frees dev, but then still falls through to\natomisp_register_i2c_module(). This results in use-after-free.\n\nIf atomisp_register_i2c_module() fails, the media entity and control\nhandler are left initialized and dev is leaked.\n\ngc2235_remove() unconditionally calls media_entity_cleanup() and\nv4l2_ctrl_handler_free(), but these are not initialized at every\nerror path in gc2235_probe().\n\nReplace gc2235_remove() calls in the probe error paths with explicit\nunwind labels that free only the resources initialized at each point\nof failure, in reverse order of initialization."
}
],
"lastModified": "2026-10-05T06:16:58.960",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}