Description
In the Linux kernel, the following vulnerability has been resolved:

media: stm32: dcmi: fix some error handling bugs in probe()

There are a few issues here:

1) After we assign:
chan = dma_request_chan(&pdev->dev, "tx");
Then the error paths need to clean up before returning. The first
error path does a direct return.
2) The error paths check "dcmi->mdma_chan" but that is not assigned
until later so it results in memory leaks. Test "mdma_chan"
instead.
3) The error handling calls dma_release_channel(dcmi->dma_chan) before
"dcmi->dma_chan" has been assigned which leads to a NULL pointer
dereference. Use the "chan" variable instead.

I also moved the call to dma_release_channel() after the call to
dma_release_channel() so it mirrors the allocation code better.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash via null pointer dereference
Action: Apply Patch
AI Analysis

Impact

The vulnerability involves errors in the Linux kernel’s stm32 DCMI media driver during probe(). The bug causes a null pointer dereference by calling dma_release_channel on an uninitialized pointer, which can lead to a kernel crash. Additionally, the code fails to clean up allocated resources on error paths, resulting in memory leaks. These issues are triggered during driver initialization and do not require special conditions beyond loading the driver.

Affected Systems

The affected systems are Linux kernel builds that include the stm32 DCMI driver. Specific version ranges are not identified in the advisory, so all kernel releases prior to the patch that contain the described code are potentially impacted. The vulnerability is present on any platform that compiles this driver, regardless of distribution.

Risk and Exploitability

The EPSS score indicates that the likelihood of exploitation is very low (<1%). The vulnerability is not listed in the CISA KEV catalog, reflecting limited widespread exploitation. Because the flaw occurs in kernel initialization, an attacker must be able to load or trigger the driver, which typically requires local or privileged access. The absence of a CVSS score limits precise severity quantification, but the potential for a system crash warrants prompt mitigation.

Generated by OpenCVE AI on September 19, 2026 at 05:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel version that includes the commits addressing the DCMI driver fix
  • If an upgrade is not immediately possible, disable the stm32 DCMI driver by blacklisting the module or turning off its support at boot
  • Monitor kernel logs for panic or BUG_NOTI entries related to media driver failures

Generated by OpenCVE AI on September 19, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: fix some error handling bugs in probe() There are a few issues here: 1) After we assign: chan = dma_request_chan(&pdev->dev, "tx"); Then the error paths need to clean up before returning. The first error path does a direct return. 2) The error paths check "dcmi->mdma_chan" but that is not assigned until later so it results in memory leaks. Test "mdma_chan" instead. 3) The error handling calls dma_release_channel(dcmi->dma_chan) before "dcmi->dma_chan" has been assigned which leads to a NULL pointer dereference. Use the "chan" variable instead. I also moved the call to dma_release_channel() after the call to dma_release_channel() so it mirrors the allocation code better.
Title media: stm32: dcmi: fix some error handling bugs in probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:34.122Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90405

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.357

Modified: 2026-09-17T17:17:40.357

Link: CVE-2026-90405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:00:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-476

    NULL Pointer Dereference