Description
In the Linux kernel, the following vulnerability has been resolved:

media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure

kthread_run() returns an ERR_PTR on failure, not NULL.
When start_streaming() fails, data->kthread_vid_cap is left holding
this error pointer instead of being cleared.

This causes two subsequent bugs:
1. A future call to start_streaming() sees a non-NULL kthread_vid_cap
and returns 0 (success) immediately, without actually starting the
capture thread.
2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which
is false for an error pointer, and proceeds to call kthread_stop()
on the error pointer, leading to a kernel crash.

Fix this by resetting kthread_vid_cap to NULL on failure before
jumping to the error path.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Crash)
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Linux media video-i2c subsystem, where the kthread_run() function incorrectly returns an error pointer rather than NULL when thread creation fails. The start_streaming() routine preserves this error pointer in data->kthread_vid_cap. A later invocation of start_streaming() mistakenly interprets the non-NULL pointer as a successful start and returns success without actually spawning the thread. When stop_streaming() later encounters this stale error pointer it attempts to stop it via kthread_stop(), leading to an immediate kernel crash. The crash abruptly halts system operation, effectively denying availability services that rely on the media subsystem. The defect is a classic case of missing error handling and dangling pointer usage.

Affected Systems

All Linux kernel releases that contain the bug in the video-i2c subsystem are vulnerable. The specific versions are not enumerated in the advisory; any maintainers or users deploying the affected commits from the kernel series referenced in the advisory should consider their installations at risk. Updates after the defensive commit that clears kthread_vid_cap on failure will eliminate this issue.

Risk and Exploitability

The CVSS base score is not disclosed, but the impact is severe, leading to a kernel panic. The EPSS score is reported as < 1%, indicating a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged context that can trigger the media driver (e.g., a malicious application that forces start_streaming() and stop_streaming() calls); the failure becomes evident only when the error path is taken. Given the low exploitation probability but catastrophic impact, a timely update remains critical.

Generated by OpenCVE AI on September 18, 2026 at 08:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch for the video-i2c subsystem that clears kthread_vid_cap on failure
  • Recompile custom kernel modules or patches that employ the affected video-i2c code after the kernel update to ensure the corrected logic is in place
  • If an immediate kernel update is not feasible, disable or unload the media video-i2c module until the bug is resolved
  • After applying the update, monitor system logs (dmesg, /var/log/kern.log) for any unexpected crash reports to confirm remediation

Generated by OpenCVE AI on September 18, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-590
CWE-676

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure kthread_run() returns an ERR_PTR on failure, not NULL. When start_streaming() fails, data->kthread_vid_cap is left holding this error pointer instead of being cleared. This causes two subsequent bugs: 1. A future call to start_streaming() sees a non-NULL kthread_vid_cap and returns 0 (success) immediately, without actually starting the capture thread. 2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which is false for an error pointer, and proceeds to call kthread_stop() on the error pointer, leading to a kernel crash. Fix this by resetting kthread_vid_cap to NULL on failure before jumping to the error path.
Title media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:39.961Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.287

Modified: 2026-09-16T11:16:55.287

Link: CVE-2026-89871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-590

    Free of Memory not on the Heap

  • CWE-676

    Use of Potentially Dangerous Function