CVE-2026-68203: media: vivid: fix cleanup bugs in vivid_init()

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081011-CVE-2026-68203-0103@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

media: vivid: fix cleanup bugs in vivid_init()

When platform_device_register() fails in vivid_init(), the embedded
struct device in vivid_pdev has already been initialized by
device_initialize(), but the failure path jumps to free_output_strings
without dropping the device reference for the current platform device:

  vivid_init()
    -> platform_device_register(&vivid_pdev)
       -> device_initialize(&vivid_pdev.dev)
       -> setup_pdev_dma_masks(&vivid_pdev)
       -> platform_device_add(&vivid_pdev)

This leads to a reference leak when platform_device_register() fails.
Fix this by calling platform_device_put() before jumping to the common
cleanup path.

Also, the unreg_driver label incorrectly calls
platform_driver_register() instead of platform_driver_unregister(),
which breaks cleanup when workqueue creation fails after successful
driver registration. Fix that as well.

The reference leak was identified by a static analysis tool I developed
and confirmed by manual review. The incorrect cleanup call was found
during code inspection.

The Linux kernel CVE team has assigned CVE-2026-68203 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 6.12.101 with commit 4385092a86b94e1f332db35a3766108978c0722f
	Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 6.18.42 with commit 1349af7f87df57940619f5b87990b799dac9ed8a
	Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 7.1.6 with commit 6d51ad8f1c50c50d1abcc97fd243179967184c6a
	Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 7.2-rc1 with commit a07c179a92e949172ca52f6d4a13202ea88cd4b7

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68203
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/media/test-drivers/vivid/vivid-core.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/4385092a86b94e1f332db35a3766108978c0722f
	https://git.kernel.org/stable/c/1349af7f87df57940619f5b87990b799dac9ed8a
	https://git.kernel.org/stable/c/6d51ad8f1c50c50d1abcc97fd243179967184c6a
	https://git.kernel.org/stable/c/a07c179a92e949172ca52f6d4a13202ea88cd4b7
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.