Description
In the Linux kernel, the following vulnerability has been resolved:

Revert "media: v4l2-dev: fix error handling in __video_register_device()"

This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a.

The intentions of that patch were good, but it doesn't work.

The idea is that if device_register fails, you have to do a put_device
to let the ref counter release resources.

However, the V4L2 API says that if video_register_device() fails, then
you have to call video_device_release(), which kfree()s the video_device
struct.

But the put_device() will already have freed the struct, so you end
up in a double-free scenario.

There is not really a good way of fixing this without breaking
video_register_device() into two parts, one that initializes everything,
and one that does the actual device_register, and then converting all
V4L2 drivers to this new model.

That is a massive job, and it is very unlikely that device_register
will fail.

So rather than ending up in a double-free scenario, just revert this
patch, and in that case we'll have a small memory leak. Which is a lot
more robust.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Double‑free in V4L2 device registration causing memory corruption
Action: Patch Kernel
AI Analysis

Impact

A double‑free bug exists in the Linux kernel’s V4L2 video device registration path. When device_register fails, the kernel frees the same video_device structure twice, corrupting kernel memory. This flaw can cause crashes or memory corruption and is identified as CWE‑1341.

Affected Systems

Linux kernel implementations that contain the original commit (2a934fdb01db6458288fc9386d3d8ceba6dd551a) and have not applied the revert. Any that kernel and employing V4L2 drivers is affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. With an EPSS score of less than 1%, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires a local user to trigger a V4L2 video device registration attempt that fails, leading to a double‑free. Remote exploitation is unlikely due to the need for kernel-level interaction.

Generated by OpenCVE AI on September 15, 2026 at 19:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the revert commit, eliminating the double‑free bug.
  • If a kernel upgrade is unavailable, apply the specific patch that reverts the faulty commit to the kernel source and rebuild.
  • If video functionality is not required, temporarily disable or restrict V4L2 video device drivers until the kernel can be updated.
  • Monitor system logs for kernel OOPS or PANIC messages that might indicate memory corruption.

Generated by OpenCVE AI on September 15, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-dev: fix error handling in __video_register_device()" This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a. The intentions of that patch were good, but it doesn't work. The idea is that if device_register fails, you have to do a put_device to let the ref counter release resources. However, the V4L2 API says that if video_register_device() fails, then you have to call video_device_release(), which kfree()s the video_device struct. But the put_device() will already have freed the struct, so you end up in a double-free scenario. There is not really a good way of fixing this without breaking video_register_device() into two parts, one that initializes everything, and one that does the actual device_register, and then converting all V4L2 drivers to this new model. That is a massive job, and it is very unlikely that device_register will fail. So rather than ending up in a double-free scenario, just revert this patch, and in that case we'll have a small memory leak. Which is a lot more robust.
Title Revert "media: v4l2-dev: fix error handling in __video_register_device()"
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:24.621Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89741

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.720

Modified: 2026-09-14T13:19:22.870

Link: CVE-2026-89741

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:47Z

Links: CVE-2026-89741 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-1341

    Multiple Releases of Same Resource or Handle