Bug 2532384 (CVE-2026-89741) - CVE-2026-89741 kernel: Linux kernel (v4l2-dev): Double-free vulnerability due to incorrect error handling
Summary: CVE-2026-89741 kernel: Linux kernel (v4l2-dev): Double-free vulnerability due...
Keywords:
Status: NEW
Alias: CVE-2026-89741
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 22:40 UTC by OSIDB Bzimport
Modified: 2026-09-11 22:57 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 22:40:54 UTC
In the Linux kernel, the following vulnerability has been resolved:

Revert "media: v4l2-dev: fix error handling in __video_register_device()"

This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a.

The intentions of that patch were good, but it doesn't work.

The idea is that if device_register fails, you have to do a put_device
to let the ref counter release resources.

However, the V4L2 API says that if video_register_device() fails, then
you have to call video_device_release(), which kfree()s the video_device
struct.

But the put_device() will already have freed the struct, so you end
up in a double-free scenario.

There is not really a good way of fixing this without breaking
video_register_device() into two parts, one that initializes everything,
and one that does the actual device_register, and then converting all
V4L2 drivers to this new model.

That is a massive job, and it is very unlikely that device_register
will fail.

So rather than ending up in a double-free scenario, just revert this
patch, and in that case we'll have a small memory leak. Which is a lot
more robust.


Note You need to log in before you can comment on or make changes to this bug.