« Volver al listado

CVE-2026-89886

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

media: intel/ipu6: fix async notifier cleanup leak on parse error

isys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode remote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an endpoint parse or add fails partway through the loop, it jumps to err_parse and returns without calling v4l2_async_nf_cleanup(), leaking every v4l2_async_connection already added to the notifier's waiting list.

The register-failure path just below already cleans up correctly, and the caller only tears the notifier down (isys_notifier_cleanup()) once isys_notifier_init() has returned success. Clean up the notifier on the parse error path too.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89886",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f50c4ca0a82003b8a542c3332fd292cf1bc355a2",
              "lessThan": "dd5943aedbe4d7eb46158cb35078257733ac48b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50c4ca0a82003b8a542c3332fd292cf1bc355a2",
              "lessThan": "27b7997be552ee37b3e01beacfeb4131f1bebb5f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50c4ca0a82003b8a542c3332fd292cf1bc355a2",
              "lessThan": "eee6069e4e9511e814a33a75e403f7e863f70394",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50c4ca0a82003b8a542c3332fd292cf1bc355a2",
              "lessThan": "abb1f808ceab5a3275f8a6b4e37cff17f9f781c1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/pci/intel/ipu6/ipu6-isys.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/pci/intel/ipu6/ipu6-isys.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:57.100",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/27b7997be552ee37b3e01beacfeb4131f1bebb5f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/abb1f808ceab5a3275f8a6b4e37cff17f9f781c1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd5943aedbe4d7eb46158cb35078257733ac48b6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eee6069e4e9511e814a33a75e403f7e863f70394",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: intel/ipu6: fix async notifier cleanup leak on parse error\n\nisys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode\nremote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an\nendpoint parse or add fails partway through the loop, it jumps to\nerr_parse and returns without calling v4l2_async_nf_cleanup(), leaking\nevery v4l2_async_connection already added to the notifier's waiting\nlist.\n\nThe register-failure path just below already cleans up correctly, and\nthe caller only tears the notifier down (isys_notifier_cleanup()) once\nisys_notifier_init() has returned success. Clean up the notifier on the\nparse error path too."
    }
  ],
  "lastModified": "2026-09-16T11:16:57.100",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}