CVE-2026-68214
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832: fix use-after-free in rtl2832_remove()
cancel_delayed_work_sync() is called before i2c_mux_del_adapters() in rtl2832_remove(). While the cancel waits for any running instance of i2c_gate_work to finish, it does not prevent the timer from being rescheduled by a concurrent thread.
During probe, the r820t_attach() call attempts I2C transfers through the mux adapter. These transfers go through i2c_mux_master_xfer(), which calls rtl2832_deselect() after the transfer completes, rescheduling i2c_gate_work via schedule_delayed_work(). If this transfer is still in flight when rtl2832_remove() runs, rtl2832_deselect() can reschedule i2c_gate_work after it has been cancelled, causing a use-after-free when kfree(dev) is called.
Leer descripción completaMostrar menos
Fix this by calling i2c_mux_del_adapters() before cancel_delayed_work_sync(). Once the mux adapter is unregistered, no new I2C transfers can go through it, so rtl2832_deselect() can no longer reschedule i2c_gate_work. The subsequent cancel_delayed_work_sync() is then guaranteed to be final.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516
- https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2
- https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309
- https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042
- https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c
- https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299
- https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750
- https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68214",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "1e8a6bc19403661661fed5ae82f6eca6c9cdfad2",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "68a9c0290897c1436ddceb8cea604c93377a0299",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "13c06056699e66ff7109ba68658cc6ea4a23f516",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "9acd5bbbe1df8e487e49488692c224496d4c9e16",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "24bef237eef8dd1ebcffb129ba21891ddad0d309",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "2c71bda6edc630a1f8c3c45d8df5fc22d234e042",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "90d781711418881f8c836c2a859cc2886625d750",
"versionType": "git"
},
{
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"lessThan": "680daf40a82d483949f87f0d8f98639dc47e610c",
"versionType": "git"
}
],
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:09.287",
"references": [
{
"url": "https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832: fix use-after-free in rtl2832_remove()\n\ncancel_delayed_work_sync() is called before i2c_mux_del_adapters()\nin rtl2832_remove(). While the cancel waits for any running instance\nof i2c_gate_work to finish, it does not prevent the timer from being\nrescheduled by a concurrent thread.\n\nDuring probe, the r820t_attach() call attempts I2C transfers through\nthe mux adapter. These transfers go through i2c_mux_master_xfer(),\nwhich calls rtl2832_deselect() after the transfer completes,\nrescheduling i2c_gate_work via schedule_delayed_work(). If this\ntransfer is still in flight when rtl2832_remove() runs,\nrtl2832_deselect() can reschedule i2c_gate_work after it has been\ncancelled, causing a use-after-free when kfree(dev) is called.\n\nFix this by calling i2c_mux_del_adapters() before\ncancel_delayed_work_sync(). Once the mux adapter is unregistered, no\nnew I2C transfers can go through it, so rtl2832_deselect() can no\nlonger reschedule i2c_gate_work. The subsequent\ncancel_delayed_work_sync() is then guaranteed to be final."
}
],
"lastModified": "2026-08-19T17:20:37.390",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}