CVE-2026-68203: media: vivid: fix cleanup bugs in vivid_init()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081011-CVE-2026-68203-0103@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix cleanup bugs in vivid_init() When platform_device_register() fails in vivid_init(), the embedded struct device in vivid_pdev has already been initialized by device_initialize(), but the failure path jumps to free_output_strings without dropping the device reference for the current platform device: vivid_init() -> platform_device_register(&vivid_pdev) -> device_initialize(&vivid_pdev.dev) -> setup_pdev_dma_masks(&vivid_pdev) -> platform_device_add(&vivid_pdev) This leads to a reference leak when platform_device_register() fails. Fix this by calling platform_device_put() before jumping to the common cleanup path. Also, the unreg_driver label incorrectly calls platform_driver_register() instead of platform_driver_unregister(), which breaks cleanup when workqueue creation fails after successful driver registration. Fix that as well. The reference leak was identified by a static analysis tool I developed and confirmed by manual review. The incorrect cleanup call was found during code inspection. The Linux kernel CVE team has assigned CVE-2026-68203 to this issue. Affected and fixed versions =========================== Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 6.12.101 with commit 4385092a86b94e1f332db35a3766108978c0722f Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 6.18.42 with commit 1349af7f87df57940619f5b87990b799dac9ed8a Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 7.1.6 with commit 6d51ad8f1c50c50d1abcc97fd243179967184c6a Issue introduced in 4.1 with commit f46d740fb0258982f00ffdbddc6486e674edafb5 and fixed in 7.2-rc1 with commit a07c179a92e949172ca52f6d4a13202ea88cd4b7 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68203 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/media/test-drivers/vivid/vivid-core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/4385092a86b94e1f332db35a3766108978c0722f https://git.kernel.org/stable/c/1349af7f87df57940619f5b87990b799dac9ed8a https://git.kernel.org/stable/c/6d51ad8f1c50c50d1abcc97fd243179967184c6a https://git.kernel.org/stable/c/a07c179a92e949172ca52f6d4a13202ea88cd4b7