Description
In the Linux kernel, the following vulnerability has been resolved:

media: i2c: ov7740: fix use-after-destroy in remove

The ov7740_remove() function had a severe teardown order bug where it
destroyed the driver's mutex before freeing the V4L2 control handler
which relies on that mutex, leading to a use-after-destroy kernel panic.
Furthermore, the driver explicitly called v4l2_ctrl_handler_free() and
mutex_destroy() sequentially, but then called ov7740_free_controls()
which invokes both of them a second time, resulting in a double-free.

This patch fixes the issue by unregistering the subdevice first, and
relying exclusively on ov7740_free_controls() to safely tear down the
mutex and control handler in the correct order.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel panic leading to denial of service
Action: Patch immediately
AI Analysis

Impact

A use‑after‑destroy bug in the Linux kernel’s ov7740 camera driver caused the driver’s mutex to be destroyed before its V4L2 control handler was freed, leading to a kernel panic during device teardown. The driver also called the cleanup function twice, triggering a double‑free that corrupts kernel memory. The flaw does not provide privilege escalation or remote code execution; its primary impact is the loss of availability due to a kernel crash, which could halt all processes on a affected system. The likely attack vector involves triggering the driver's removal sequence, which requires local interaction with the device or privileged access to the I2C bus. Based on the description, it is inferred that an attacker would need to unload the driver or manipulate the device’s state to cause the bug.

Affected Systems

All Linux kernel builds that include the ov7740 driver and have not applied the patch at commit 09453b467990e8ef8fe09f45a685f9a625248d33 are vulnerable. The affected versions encompass any kernel where the ov7740 sub‑device is enabled, regardless of major or minor version, since the vulnerability exists in all pre‑patched releases that contain the driver.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity bug, yet the EPSS score of less than 1% reflects a very low current probability that this vulnerability will be exploited. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation would require local control of the device or the capacity to trigger its removal sequence, which likely necessitates privileged access to the I2C bus or the ability to unload the driver. No remote exploitation or privilege escalation is described, so the main risk remains a denial‑of‑service via a kernel panic.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the ov7740 removal fix (commit 09453b467990e8ef8fe09f45a685f9a625248d33).
  • If an update is not immediately possible, disable or unload the ov7740 driver so the device is not initialized, preventing the teardown sequence that triggers the bug.
  • Restrict I2C bus access and kernel module loading to trusted users only, and ensure that the ov7740 device is not exposed to untrusted processes.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov7740: fix use-after-destroy in remove The ov7740_remove() function had a severe teardown order bug where it destroyed the driver's mutex before freeing the V4L2 control handler which relies on that mutex, leading to a use-after-destroy kernel panic. Furthermore, the driver explicitly called v4l2_ctrl_handler_free() and mutex_destroy() sequentially, but then called ov7740_free_controls() which invokes both of them a second time, resulting in a double-free. This patch fixes the issue by unregistering the subdevice first, and relying exclusively on ov7740_free_controls() to safely tear down the mutex and control handler in the correct order.
Title media: i2c: ov7740: fix use-after-destroy in remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:37.116Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89887

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.210

Modified: 2026-09-16T15:18:15.230

Link: CVE-2026-89887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses