Description
In the Linux kernel, the following vulnerability has been resolved:

media: rc: sunxi-cir: Unregister rc device on probe failure

After rc_register_device() succeeds, later probe failures must undo the
registration with rc_unregister_device(). The current error path jumps to
the allocation cleanup label and only calls rc_free_device(), leaving the
rc device registration and resources created by rc_register_device()
behind.

Add a registered-device unwind label for the IRQ lookup, IRQ request, and
hardware initialization failure paths. Keep rc_free_device() for failures
before rc_register_device() succeeds.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in the media rc driver sunxi-cir, where a successful rc_register_device registration is not undone when subsequent probe stages fail. The kernel only frees the device structure instead of unregistering the device, leaving the rc device registered and its resources tied up. This can lead to resource exhaustion, potentially preventing new RC devices from being registered and causing denial of service.

Affected Systems

All Linux kernel releases that include the media rc sunxi-cir driver and that have not yet applied the patch are affected. The vendor information lists Linux:Linux, indicating that any distribution shipping the default kernel configuration with this driver is a risk. No specific version numbers are provided, so the issue applies until the fix is made available in a kernel update.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity, and the EPSS score of less than 1% indicates that exploitation is currently unlikely but still plausible. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to trigger a probe failure of the sunxi-cir device, which typically requires local access to the hardware or the ability to load the kernel module. If an attacker can repeatedly cause such failures, they may exhaust the limited device slots and prevent normal operation, resulting in a denial of service. The patch mitigates this by adding an unwind path that performs rc_unregister_device on all error scenarios.

Generated by OpenCVE AI on September 18, 2026 at 08:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Linux kernel that includes the patch for the sunxi-cir media rc driver, ensuring rc_unregister_device is called on probe failures.
  • If a kernel update cannot be applied immediately, disable the sunxi-cir rc driver by removing it from the kernel configuration or unloading the module to prevent uncontrolled device registration.
  • As a temporary measure, avoid operations that cause probe failures on the sunxi-cir device, or reset the device after failure to force a clean state, noting this is not a permanent solution.

Generated by OpenCVE AI on September 18, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe failure After rc_register_device() succeeds, later probe failures must undo the registration with rc_unregister_device(). The current error path jumps to the allocation cleanup label and only calls rc_free_device(), leaving the rc device registration and resources created by rc_register_device() behind. Add a registered-device unwind label for the IRQ lookup, IRQ request, and hardware initialization failure paths. Keep rc_free_device() for failures before rc_register_device() succeeds.
Title media: rc: sunxi-cir: Unregister rc device on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:34.436Z

Reserved: 2026-09-11T19:38:34.772Z

Link: CVE-2026-89883

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:56.753

Modified: 2026-09-16T15:18:14.963

Link: CVE-2026-89883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption