Description
In the Linux kernel, the following vulnerability has been resolved:

media: cedrus: fix memory leak in cedrus_init_ctrls()

In cedrus_init_ctrls(), the V4L2 control handler is initialized before
allocating memory for ctx->ctrls. If this allocation fails, the function
returns -ENOMEM without freeing the previously allocated handler
resources, leading to a memory leak.

Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation
failure path.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an
Allwinner SoC or board with a Cedrus VPU available to test with, no
runtime testing was able to be performed.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (memory exhaustion)
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel the cedrus VPU driver contains a memory leak in the initialization of its V4L2 control handler. The handler is set up before memory for the control structure is allocated; if the allocation fails the function returns an error but does not free the previously allocated handler, leaking kernel memory. Repeated or forced failures could gradually exhaust memory, destabilize the kernel, and lead to a denial‑of‑service condition.

Affected Systems

The issue appears in the Linux kernel, affecting all distributions that ship the cedrus driver prior to the patch that fixes the leak (confirmed present in v7.1.1 and earlier). No specific vendor or product version lists are provided beyond the general Linux kernel.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a very low probability of exploitation. The impact is local; an attacker with the ability to trigger the cedrus driver initialization repeatedly could attempt to force a memory exhaustion state. However, the low exploit probability combined with the lack of public exploitation makes the threat moderate at best.

Generated by OpenCVE AI on September 18, 2026 at 07:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the cedrus memory‑leak fix
  • If an update is not immediately possible, disable or unload the cedrus VPU driver to prevent the code path from executing
  • Deploy kernel memory monitoring to detect abnormal memory growth and trigger alerts if a leak is suspected
  • Consider applying limits to V4L2 control allocations via kernel tuning parameters if supported by the distribution

Generated by OpenCVE AI on September 18, 2026 at 07:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: cedrus: fix memory leak in cedrus_init_ctrls() In cedrus_init_ctrls(), the V4L2 control handler is initialized before allocating memory for ctx->ctrls. If this allocation fails, the function returns -ENOMEM without freeing the previously allocated handler resources, leading to a memory leak. Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation failure path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64 allyesconfig build showed no new warnings. As we do not have an Allwinner SoC or board with a Cedrus VPU available to test with, no runtime testing was able to be performed.
Title media: cedrus: fix memory leak in cedrus_init_ctrls()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:57.504Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:58.400

Modified: 2026-09-16T11:16:58.400

Link: CVE-2026-89896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime