« Volver al listado

CVE-2026-89901

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref

airspy_disconnect() clears s->udev under v4l2_lock, but airspy_stop_streaming() unconditionally calls airspy_ctrl_msg() and airspy_free_stream_bufs() afterwards. If a streaming user closes the device after disconnect, stop_streaming() runs and dereferences the NULL s->udev:

The airspy driver uses vb2_fop_release() in its file_operations, so replace video_unregister_device(&s->vdev) with vb2_video_unregister_device(&s->vdev) and move it before clearing s->udev. vb2_video_unregister_device() releases the vb2 queue, which synchronously runs airspy_stop_streaming() if streaming is active, so the URBs, coherent DMA stream buffers and the hardware stop control message all execute while s->udev is still valid.

Leer descripción completaMostrar menos

vb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock) internally, and stop_streaming() locks v4l2_lock, so the previous outer mutex_lock(&s->vb_queue_lock) / mutex_lock(&s->v4l2_lock) pair around the unregister sequence would self-deadlock and has been removed. A short v4l2_lock critical section around s->udev = NULL remains so any ioctl path that still holds the file descriptor sees coherent state.

Issue identified by automated review of the INV-003 series at https://sashiko.dev/

Detalles técnicos trazas, registros y código del informe original
  airspy_stop_streaming()
    airspy_ctrl_msg(s, CMD_RECEIVER_MODE, 0, 0, NULL, 0)
      usb_sndctrlpipe(s->udev, 0)         /* NULL deref */
    airspy_free_stream_bufs(s)
      usb_free_coherent(s->udev, ...)     /* NULL deref */

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89901",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "c9081e2655188d2d134a741aec837dc70439d505",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "75089cea32e5055773bd13116236d08fdc98678a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "155d0378ae0d6305cc4840583a6b42d2d0595bff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "6e4ea90fdc6608cd5fac342e146ab6ae15d430bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "a9a8c37ddda9fa3687b142be9098e1c37b8faf35",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "297fee023f46d771a844520675692ea089d80d9d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "c6749ac8f59cc80eb1b2d52f167fdf13e12655cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
              "lessThan": "2f378dc45e685fc825d2dd08e7864666d6fcc009",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/usb/airspy/airspy.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/usb/airspy/airspy.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:59.003",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/155d0378ae0d6305cc4840583a6b42d2d0595bff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/297fee023f46d771a844520675692ea089d80d9d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2f378dc45e685fc825d2dd08e7864666d6fcc009",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e4ea90fdc6608cd5fac342e146ab6ae15d430bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/75089cea32e5055773bd13116236d08fdc98678a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a9a8c37ddda9fa3687b142be9098e1c37b8faf35",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c6749ac8f59cc80eb1b2d52f167fdf13e12655cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9081e2655188d2d134a741aec837dc70439d505",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref\n\nairspy_disconnect() clears s->udev under v4l2_lock, but\nairspy_stop_streaming() unconditionally calls airspy_ctrl_msg() and\nairspy_free_stream_bufs() afterwards. If a streaming user closes the\ndevice after disconnect, stop_streaming() runs and dereferences the\nNULL s->udev:\n\n  airspy_stop_streaming()\n    airspy_ctrl_msg(s, CMD_RECEIVER_MODE, 0, 0, NULL, 0)\n      usb_sndctrlpipe(s->udev, 0)         /* NULL deref */\n    airspy_free_stream_bufs(s)\n      usb_free_coherent(s->udev, ...)     /* NULL deref */\n\nThe airspy driver uses vb2_fop_release() in its file_operations, so\nreplace video_unregister_device(&s->vdev) with\nvb2_video_unregister_device(&s->vdev) and move it before clearing\ns->udev. vb2_video_unregister_device() releases the vb2 queue, which\nsynchronously runs airspy_stop_streaming() if streaming is active, so\nthe URBs, coherent DMA stream buffers and the hardware stop control\nmessage all execute while s->udev is still valid.\n\nvb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock)\ninternally, and stop_streaming() locks v4l2_lock, so the previous outer\nmutex_lock(&s->vb_queue_lock) / mutex_lock(&s->v4l2_lock) pair around\nthe unregister sequence would self-deadlock and has been removed. A\nshort v4l2_lock critical section around s->udev = NULL remains so any\nioctl path that still holds the file descriptor sees coherent state.\n\nIssue identified by automated review of the INV-003 series at\nhttps://sashiko.dev/"
    }
  ],
  "lastModified": "2026-09-16T11:16:59.003",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}