Description
In the Linux kernel, the following vulnerability has been resolved:

media: bcm2835-unicam: Fix asc leaked in error/remove path

v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed when
v4l2_async_nf_cleanup() is called.

Call v4l2_async_nf_cleanup() properly in the driver paths.

Discovered with kmemleak after rmmod:

unreferenced object 0xffff000084526b80 (size 64):
comm "modprobe", pid 185, jiffies 4295013512
hex dump (first 32 bytes):
01 00 00 00 00 00 00 00 e8 0d ff bf 00 00 ff ff ................
40 83 bc 84 00 00 ff ff 60 83 bc 84 00 00 ff ff @.......`.......
backtrace (crc ac584083):
[<00000000ffb081a7>] kmemleak_alloc+0x38/0x44
[<00000000d2fd9301>] __kmalloc+0x1b0/0x250
[<000000004dd5354d>] __v4l2_async_nf_add_fwnode+0x28/0x9c
[<0000000067587657>] __v4l2_async_nf_add_fwnode_remote+0x3c/0x64
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak leading to information disclosure
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel media subsystem, the bcm2835-unicam driver allocates an asynchronous callback structure during device registration but never frees it when the module unloads or an error occurs. The unfreed structure persists in kernel memory, which the memory‑leak detector identifies as a leak. While this flaw does not enable direct, the leaked data may contain sensitive kernel information that could be read by a local attacker, potentially exposing confidential data or affecting system stability through memory pressure.

Affected Systems

All Linux kernel builds that include the bcm2835-unicam driver, typically found on devices using the BCM2835 SoC such as Raspberry Pi boards and other ARM-based embedded systems, are affected. The CVE does not list specific kernel versions, so any build lacking the upstream commit that releases the freed asc should be treated as vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, implying a low likelihood of exploitation. Based on the description, it is inferred that an attacker would need local access or privileged execution to unload the driver or trigger the error path that causes the leak. No publicly documented remote attack vector exists, and the flaw does not enable arbitrary code execution.

Generated by OpenCVE AI on September 19, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that includes the commit adding an explicit cleanup for the asynchronous callback structure, such as the commit referenced by the provided git URLs.
  • If an immediate kernel upgrade is not feasible, blacklist the bcm2835‑unicam module to prevent it from loading—add a blacklist line to /etc/modprobe.d or load rmmod before rebooting the system.
  • Optionally, rebuild the kernel from source applying the upstream patch manually by cherry‑picking the commit that frees the asc structure; compile, install, and reboot to eliminate the leak.

Generated by OpenCVE AI on September 19, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: bcm2835-unicam: Fix asc leaked in error/remove path v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed when v4l2_async_nf_cleanup() is called. Call v4l2_async_nf_cleanup() properly in the driver paths. Discovered with kmemleak after rmmod: unreferenced object 0xffff000084526b80 (size 64): comm "modprobe", pid 185, jiffies 4295013512 hex dump (first 32 bytes): 01 00 00 00 00 00 00 00 e8 0d ff bf 00 00 ff ff ................ 40 83 bc 84 00 00 ff ff 60 83 bc 84 00 00 ff ff @.......`....... backtrace (crc ac584083): [<00000000ffb081a7>] kmemleak_alloc+0x38/0x44 [<00000000d2fd9301>] __kmalloc+0x1b0/0x250 [<000000004dd5354d>] __v4l2_async_nf_add_fwnode+0x28/0x9c [<0000000067587657>] __v4l2_async_nf_add_fwnode_remote+0x3c/0x64
Title media: bcm2835-unicam: Fix asc leaked in error/remove path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:55.092Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.977

Modified: 2026-09-17T17:18:00.977

Link: CVE-2026-93071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-401

    Missing Release of Memory after Effective Lifetime