Description
In the Linux kernel, the following vulnerability has been resolved:

media: intel/ipu6: fix async notifier cleanup leak on parse error

isys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode
remote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an
endpoint parse or add fails partway through the loop, it jumps to
err_parse and returns without calling v4l2_async_nf_cleanup(), leaking
every v4l2_async_connection already added to the notifier's waiting
list.

The register-failure path just below already cleans up correctly, and
the caller only tears the notifier down (isys_notifier_cleanup()) once
isys_notifier_init() has returned success. Clean up the notifier on the
parse error path too.
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak with potential Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Intel IPU6 media driver in the Linux kernel contains a flaw where asynchronous notifier initialization does not invoke the cleanup routine if a parse error occurs during the addition of fwnode remote subdevices. This omission causes all previously added v4l2_async_connection objects to remain in the notifier’s waiting list, leaking kernel memory and other resources Persistently leaked connections can build up over time, potentially exhausting kernel memory or connection limits and degrading system stability or availability.

Affected Systems

All Linux kernel builds that include the unpatched Intel IPU6 media driver are affected. No specific kernel version numbers are listed, so any kernel image or module that ships the Intel IPU6 driver before the patch is vulnerable.

Risk and Exploitability

The EPSS score is reported as < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need privileged or kernel-level access to trigger a parse error—such as by providing malformed firmware nodes or loading a malicious driver—to provoke the leak. Even without a publicly available exploit, the resource exhaustion impact could lead to denial of service if the attacker can repeatedly trigger the parsing routine. The CVSS score of 5.5 classifies the vulnerability as moderate severity.

Generated by OpenCVE AI on September 24, 2026 at 03:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the IPU6 driver fix
  • If an immediate kernel upgrade is not feasible, disable the Intel IPU6 media driver module using systemd-modules-load.d or modprobe options
  • Ensure that no firmware nodes or modules capable of triggering the parsing routine are loaded until the patch is applied

Generated by OpenCVE AI on September 24, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix async notifier cleanup leak on parse error isys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode remote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an endpoint parse or add fails partway through the loop, it jumps to err_parse and returns without calling v4l2_async_nf_cleanup(), leaking every v4l2_async_connection already added to the notifier's waiting list. The register-failure path just below already cleans up correctly, and the caller only tears the notifier down (isys_notifier_cleanup()) once isys_notifier_init() has returned success. Clean up the notifier on the parse error path too.
Title media: intel/ipu6: fix async notifier cleanup leak on parse error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:50.497Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.100

Modified: 2026-09-16T11:16:57.100

Link: CVE-2026-89886

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89886 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T03:30:08Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime