Description
In the Linux kernel, the following vulnerability has been resolved:

media: ipu6: Do not free aux device pdata after init

ipu6_bus_initialize_device() stores the isys/psys pdata pointer in
struct ipu6_bus_device and initializes the auxiliary device. After that
point, error unwinding must drop the auxiliary device reference and let
ipu6_bus_release() free both the bus device and adev->pdata.

The isys and psys init paths already call put_device() when MMU
initialization fails, and ipu6_bus_add_device() calls
auxiliary_device_uninit() on auxiliary_device_add() failure. Both paths
therefore run the bus release callback. The extra kfree(pdata) in the
callers can release the same object a second time.

Remove the manual pdata frees after the auxiliary device has been
initialized.

This issue was found by a static analysis checker and confirmed by
manual source review.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel media driver for ipu6 contains a double‑free flaw during bus initialization. After an auxiliary device is successfully added, the driver again frees the same data structure, corrupting kernel memory and causing a crash. The result is a denial of service to the affected system.

Affected Systems

The flaw exists in all versions of the Linux kernel that include the ipu6 media driver prior to the fix. No specific kernel releases are enumerated in the advisory, so any kernel containing this driver may be vulnerable.

Risk and Exploitability

Likely attack vector involves local or privileged access to the system to trigger the ipu6 driver’s bus initialization routine. Once initiated, the driver’s double‑free logic would corrupt kernel memory and cause a crash, resulting in denial of service. The CVSS score of 7.8 signals a serious denial‑of‑service risk, while the EPSS score of less than 1 % indicates low exploitation probability. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 19, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the ipu6 driver patch removing the double‑free flaw.
  • If a kernel upgrade cannot be performed immediately, blacklist or unload the affected media modules (e.g., ipu6) until a fix is available.
  • Monitor kernel logs (e.g., dmesg) for oops or fatal errors and apply security updates as soon as they become available.

Generated by OpenCVE AI on September 19, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after init ipu6_bus_initialize_device() stores the isys/psys pdata pointer in struct ipu6_bus_device and initializes the auxiliary device. After that point, error unwinding must drop the auxiliary device reference and let ipu6_bus_release() free both the bus device and adev->pdata. The isys and psys init paths already call put_device() when MMU initialization fails, and ipu6_bus_add_device() calls auxiliary_device_uninit() on auxiliary_device_add() failure. Both paths therefore run the bus release callback. The extra kfree(pdata) in the callers can release the same object a second time. Remove the manual pdata frees after the auxiliary device has been initialized. This issue was found by a static analysis checker and confirmed by manual source review.
Title media: ipu6: Do not free aux device pdata after init
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:50.993Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.863

Modified: 2026-09-18T18:18:20.027

Link: CVE-2026-93070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses