« Volver al listado

CVE-2026-93223

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

staging: media: tegra-video: fix of_node_put() on VIP parse errors

tegra_vip_channel_of_parse() initializes np from dev->of_node without taking a reference, but its error paths drop one through the err_node_put label. This underflows the refcount of the VIP device's OF node when endpoint parsing fails on a malformed device tree.

The only reference the function takes on np is the success-path of_node_get() stored in vip->chan.of_node, and that one is already released by the tegra_vip_init() error path and by tegra_vip_exit().

Return errors directly instead of jumping to the bogus cleanup label.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93223",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e740d199cf0ff1e53ddc2ab067c0a09b55845d68",
              "lessThan": "a3783800c9475fa58b8db0885893f96a23f949da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e740d199cf0ff1e53ddc2ab067c0a09b55845d68",
              "lessThan": "1295ba29ac590bbb5c4a586afd408018168af10b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e740d199cf0ff1e53ddc2ab067c0a09b55845d68",
              "lessThan": "656d047dc0c29c0964d840217a0593f16aa9bc5e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e740d199cf0ff1e53ddc2ab067c0a09b55845d68",
              "lessThan": "fc9937019cf7e2fe4e29f9341e6400bcd2cde721",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e740d199cf0ff1e53ddc2ab067c0a09b55845d68",
              "lessThan": "7393372f79db940acff206b43e2905685a0c57ad",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/staging/media/tegra-video/vip.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/staging/media/tegra-video/vip.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:17.590",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1295ba29ac590bbb5c4a586afd408018168af10b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/656d047dc0c29c0964d840217a0593f16aa9bc5e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7393372f79db940acff206b43e2905685a0c57ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a3783800c9475fa58b8db0885893f96a23f949da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fc9937019cf7e2fe4e29f9341e6400bcd2cde721",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: tegra-video: fix of_node_put() on VIP parse errors\n\ntegra_vip_channel_of_parse() initializes np from dev->of_node without\ntaking a reference, but its error paths drop one through the\nerr_node_put label. This underflows the refcount of the VIP device's\nOF node when endpoint parsing fails on a malformed device tree.\n\nThe only reference the function takes on np is the success-path\nof_node_get() stored in vip->chan.of_node, and that one is already\nreleased by the tegra_vip_init() error path and by tegra_vip_exit().\n\nReturn errors directly instead of jumping to the bogus cleanup label."
    }
  ],
  "lastModified": "2026-09-24T16:17:17.590",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}