Description
In the Linux kernel, the following vulnerability has been resolved:

media: saa7164: fix cleanup on resource allocation failure

saa7164_dev_setup() adds the device to the global saa7164_devlist before
requesting the PCI BAR memory regions.

If get_resources() fails, saa7164_dev_setup() decrements the device count
and returns an error, but leaves the device on saa7164_devlist. The probe
error path then frees the device, leaving a dangling entry on the global
list.

Reuse the existing MMIO mapping error path to remove the device from
saa7164_devlist and decrement the device count before returning.

Also release BAR0 if it was successfully requested but the BAR2 request
fails.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The saa7164 media driver in the Linux kernel incorrectly handles resource allocation failures during device initialization. When the PCI BAR memory region request fails, the driver increments the global device list but then decrements the device count and exits, leaving a dangling entry in the list. If the probe error path is later invoked, the device is freed but the global list still contains a reference to the removed device. This flaw can lead to kernel instability, including potential system crashes or corrupted state if later code accesses the stale list entry. The vulnerability is a classic example of improper resource deallocation.

Affected Systems

All Linux kernel configurations that include the saa7164 media driver are affected. The bug originates in the media subsystem of the kernel and is present in every kernel release that ships with the saa7164 driver until the patch is applied. No specific vendor or version details are listed beyond the generic Linux kernel designation.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity with high impact. The EPSS score is less than 1%, suggesting a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local privilege or device presence; an attacker who can insert or manipulate a saa7164 device—typically a physical host or local user with kernel module loading rights—could trigger the faulty path. Exploiting this flaw would result in a denial of service or kernel crash, potentially allowing escalation to broader compromise if the crash leads to arbitrary code execution.

Generated by OpenCVE AI on September 18, 2026 at 03:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the saa7164 driver fix to remove the malformed list entry during resource allocation failures.
  • If an immediate kernel upgrade is not possible, disable the saa7164 driver or physically remove the device from the system to prevent the buggy initialization path from executing.
  • Monitor kernel logs for Oops or crash messages referencing saa7164 to detect exploitation attempts or system instability caused by the dangling list entry.

Generated by OpenCVE AI on September 18, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: saa7164: fix cleanup on resource allocation failure saa7164_dev_setup() adds the device to the global saa7164_devlist before requesting the PCI BAR memory regions. If get_resources() fails, saa7164_dev_setup() decrements the device count and returns an error, but leaves the device on saa7164_devlist. The probe error path then frees the device, leaving a dangling entry on the global list. Reuse the existing MMIO mapping error path to remove the device from saa7164_devlist and decrement the device count before returning. Also release BAR0 if it was successfully requested but the BAR2 request fails.
Title media: saa7164: fix cleanup on resource allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:30.609Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89877

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.987

Modified: 2026-09-16T15:18:14.570

Link: CVE-2026-89877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses