Description
In the Linux kernel, the following vulnerability has been resolved:

media: zoran: Avoid freeing a registered video_device twice

zoran_init_video_device() installs zoran_vdev_release() as the
video_device release callback through zoran_template. After
video_register_device() succeeds, video_unregister_device() drops the
registered video_device reference and the V4L2 core eventually invokes
that release callback, which kfree()s the video_device.

zoran_exit_video_devices() called video_unregister_device() and then
kfree(zr->video_dev), so device teardown could free the same
video_device twice.

Remove the direct kfree() and clear the cached pointer after
unregistering. The pre-registration failure path keeps its manual free
because the video_device was not registered there.

This issue was found by a static analysis checker and confirmed by
manual source review.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Privilege Escalation
Action: Update Kernel
AI Analysis

Impact

The Linux kernel media driver for Zoran hardware contains a double‑free bug, where the video_device structure is freed twice during device teardown. This leads to kernel memory corruption that could be exploited to execute arbitrary code with kernel privileges or to destabilize the system.

Affected Systems

All Linux kernel releases that include the Zoran media driver before the patch are impacted. No specific version range is provided, so any kernel that compiles the zoran.c module without the fix is potentially vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates a high‑severity flaw. The EPSS score of less than 1% suggests that the likelihood of a public exploit is low at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a local attacker who can load or interact with the Zoran device driver, making the attack vector local rather than remote.

Generated by OpenCVE AI on September 18, 2026 at 03:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the commit removing the double free from zoran.c.
  • As a temporary measure, disable or unload the zoran video driver module (e.g., add modprobe.blacklist=zoran to /etc/modprobe.d or run rmmod zoran).
  • Verify that no other modules use the unpatched zoran driver and ensure devices depending on it are either removed or upgraded to a protected driver.

Generated by OpenCVE AI on September 18, 2026 at 03:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_device twice zoran_init_video_device() installs zoran_vdev_release() as the video_device release callback through zoran_template. After video_register_device() succeeds, video_unregister_device() drops the registered video_device reference and the V4L2 core eventually invokes that release callback, which kfree()s the video_device. zoran_exit_video_devices() called video_unregister_device() and then kfree(zr->video_dev), so device teardown could free the same video_device twice. Remove the direct kfree() and clear the cached pointer after unregistering. The pre-registration failure path keeps its manual free because the video_device was not registered there. This issue was found by a static analysis checker and confirmed by manual source review.
Title media: zoran: Avoid freeing a registered video_device twice
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:26.773Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.153

Modified: 2026-09-16T15:18:14.187

Link: CVE-2026-89870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses

No weakness.