CVE-2026-68209
In the Linux kernel, the following vulnerability has been resolved:
media: sun4i-csi: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.
sun4i_csi_start_streaming() returned -EINVAL when no matching CSI format could be found, before any setup (scratch buffer allocation, pipeline start) had been performed.
Leer descripción completaMostrar menos
The remaining error paths already converge on the err_clear_dma_queue label, which calls return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump to that label directly: the intermediate err_disable_device / err_disable_pipeline / err_free_scratch_buffer labels are skipped, which is correct because nothing they would undo has happened yet.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad local (AV:L, PR:L) sin interacción que permite fuga de buffers y crash del driver CSI, resultando en DoS de aplicaciones multimedia. CWE no especificado pero el patrón de gestión incorrecta de memoria apunta a condición de carrera/corrupción de estado que un atacante local privilegiad
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d
- https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a
- https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82
- https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7
- https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54
- https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331
- https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f
- https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68209",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "4872161e6fbe4e1783daea8bff79caddfae0fb82",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "a8abecc638a7feb20b78fabd563b05e30c071331",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "668face37fdb6b6900645dc8777195498541c9a7",
"versionType": "git"
},
{
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"lessThan": "bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"versionType": "git"
}
],
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:08.637",
"references": [
{
"url": "https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed. The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"lastModified": "2026-08-19T17:20:36.807",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}