« Volver al listado

CVE-2026-68203

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

media: vivid: fix cleanup bugs in vivid_init()

When platform_device_register() fails in vivid_init(), the embedded struct device in vivid_pdev has already been initialized by device_initialize(), but the failure path jumps to free_output_strings without dropping the device reference for the current platform device:

This leads to a reference leak when platform_device_register() fails. Fix this by calling platform_device_put() before jumping to the common cleanup path.

Also, the unreg_driver label incorrectly calls platform_driver_register() instead of platform_driver_unregister(), which breaks cleanup when workqueue creation fails after successful driver registration. Fix that as well.

Leer descripción completaMostrar menos

The reference leak was identified by a static analysis tool I developed and confirmed by manual review. The incorrect cleanup call was found during code inspection.

Detalles técnicos trazas, registros y código del informe original
  vivid_init()
    -> platform_device_register(&vivid_pdev)
       -> device_initialize(&vivid_pdev.dev)
       -> setup_pdev_dma_masks(&vivid_pdev)
       -> platform_device_add(&vivid_pdev)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68203",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
              "lessThan": "4385092a86b94e1f332db35a3766108978c0722f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
              "lessThan": "1349af7f87df57940619f5b87990b799dac9ed8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
              "lessThan": "6d51ad8f1c50c50d1abcc97fd243179967184c6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
              "lessThan": "a07c179a92e949172ca52f6d4a13202ea88cd4b7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/test-drivers/vivid/vivid-core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/test-drivers/vivid/vivid-core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:07.897",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1349af7f87df57940619f5b87990b799dac9ed8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4385092a86b94e1f332db35a3766108978c0722f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6d51ad8f1c50c50d1abcc97fd243179967184c6a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a07c179a92e949172ca52f6d4a13202ea88cd4b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: fix cleanup bugs in vivid_init()\n\nWhen platform_device_register() fails in vivid_init(), the embedded\nstruct device in vivid_pdev has already been initialized by\ndevice_initialize(), but the failure path jumps to free_output_strings\nwithout dropping the device reference for the current platform device:\n\n  vivid_init()\n    -> platform_device_register(&vivid_pdev)\n       -> device_initialize(&vivid_pdev.dev)\n       -> setup_pdev_dma_masks(&vivid_pdev)\n       -> platform_device_add(&vivid_pdev)\n\nThis leads to a reference leak when platform_device_register() fails.\nFix this by calling platform_device_put() before jumping to the common\ncleanup path.\n\nAlso, the unreg_driver label incorrectly calls\nplatform_driver_register() instead of platform_driver_unregister(),\nwhich breaks cleanup when workqueue creation fails after successful\ndriver registration. Fix that as well.\n\nThe reference leak was identified by a static analysis tool I developed\nand confirmed by manual review. The incorrect cleanup call was found\nduring code inspection."
    }
  ],
  "lastModified": "2026-08-17T05:18:22.300",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}