Description
In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link

In v4l2_fwnode_parse_link(), the remote endpoint fwnode reference is
acquired using fwnode_graph_get_remote_endpoint(). This reference is
properly released in the error paths, but it is leaked on the success
path.

Add the missing fwnode_handle_put() before returning 0 to prevent the
reference leak.

[Sakari Ailus: Fix subject prefix and coding style a little.]
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak Potential Denial of Service
Action: Apply Patch
AI Analysis

Impact

A reference leak exists in the Linux kernel media subsystem’s v4l2_fwnode_parse_link function. The kernel acquires a remote endpoint reference through fwnode_graph_get_remote_endpoint() but fails to release it on successful completion. Each call therefore increments the reference count irreversibly. Over time, repeated invocations can exhaust available reference slots, causing failures in subsequent operations that depend on those references and potentially leading to a kernel resource exhaustion scenario. The flaw does not provide privilege escalation or confidentiality disclosure; its primary impact is service interruption through denial of service.

Affected Systems

All Linux kernel builds that include the media subsystem and contain the vulnerable v4l2_fwnode_parse_link implementation before the commit adding the missing fwnode_handle_put() call are affected. The issue is present across all distributors that ship such kernels, not limited to any vendor-specific variant.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that exploitation requires normal kernel operation that parses V4L2 firmware node links, so the attack vector is local via routine device usage. The severity is limited to resource exhaustion leading to service disruption; no code execution or privilege escalation can be achieved.

Generated by OpenCVE AI on September 24, 2026 at 02:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit adding fwnode_handle_put() to v4l2_fwnode_parse_link
  • Reboot the system to load the updated kernel image
  • Use kernel monitoring tools or system logs to confirm that firmware node reference counts no longer grow during operation

Generated by OpenCVE AI on September 24, 2026 at 02:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link In v4l2_fwnode_parse_link(), the remote endpoint fwnode reference is acquired using fwnode_graph_get_remote_endpoint(). This reference is properly released in the error paths, but it is leaked on the success path. Add the missing fwnode_handle_put() before returning 0 to prevent the reference leak. [Sakari Ailus: Fix subject prefix and coding style a little.]
Title media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:40.647Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89872

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.417

Modified: 2026-09-16T11:16:55.417

Link: CVE-2026-89872

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89872 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T02:45:15Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime