Description
In the Linux kernel, the following vulnerability has been resolved:

media: i2c: ov02a10: fix endpoint parsing use-after-free

The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep)
immediately after allocating and parsing the endpoint. However, it
subsequently calls fwnode_property_read_u32() using the same 'ep'
handle, leading to a potential use-after-free.

Additionally, reading the optional 'ovti,mipi-clock-voltage' property
used to overwrite the 'ret' variable. If the property was missing,
'ret' would become negative, and this failure code would be incorrectly
returned at the end of the function, causing probe to fail entirely.

Fix the use-after-free by moving fwnode_property_read_u32() before
the endpoint is parsed and freed. Avoid the error leak by not
assigning the result of fwnode_property_read_u32() to 'ret'.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The media driver for the ov02a10 camera sensor has a use‑after‑free bug. During probe the endpoint handle is released before a property read still references it, allowing corruption of kernel memory. An attacker with local access or the ability to supply a crafted device tree could trigger this flaw, potentially executing arbitrary code or causing a kernel panic. The bug also improperly handles a missing property, causing the probe to fail so the device never registers, which can lead to a denial of service for systems that rely on the sensor.

Affected Systems

All Linux kernel versions that ship the media/i2c ov02a10 driver are vulnerable. The fix is in the mainline source and will arrive in downstream distributions that build a recent kernel. Any system running a kernel that includes the unpatched driver and has the ov02a10 device enabled is at risk.

Risk and Exploitability

With a CVSS base score of 7.8 the flaw is high severity, but its EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The issue can be leveraged only by attackers that can load or modify the device tree or gain local access, so the threat is somewhat constrained. The vulnerability is listed in CISA KEV as not present, yet the potential for privilege escalation and denial of service means the risk remains significant until a patch is in place.

Generated by OpenCVE AI on September 18, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the ov02a10 fix.
  • Reboot the affected systems so the updated kernel and driver are loaded.
  • If immediate kernel upgrade is not possible, temporarily disable the i2c ov02a10 module (e.g., via module blacklist or kernel parameter) to prevent the driver from initializing until the patch is applied.
  • Verify that the device tree for the ov02a10 sensor does not contain the 'ovti,mipi-clock-voltage' property or set it to a valid value to avoid probe failure.

Generated by OpenCVE AI on September 18, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov02a10: fix endpoint parsing use-after-free The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep) immediately after allocating and parsing the endpoint. However, it subsequently calls fwnode_property_read_u32() using the same 'ep' handle, leading to a potential use-after-free. Additionally, reading the optional 'ovti,mipi-clock-voltage' property used to overwrite the 'ret' variable. If the property was missing, 'ret' would become negative, and this failure code would be incorrectly returned at the end of the function, causing probe to fail entirely. Fix the use-after-free by moving fwnode_property_read_u32() before the endpoint is parsed and freed. Avoid the error leak by not assigning the result of fwnode_property_read_u32() to 'ret'.
Title media: i2c: ov02a10: fix endpoint parsing use-after-free
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:38.808Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.347

Modified: 2026-09-16T15:18:15.367

Link: CVE-2026-89888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses