Description
In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-async: Unregister sub-device if asc_list is empty

When my em28xx USB device that uses the i2c tvp5150 driver is
disconnected, it crashes.

The cause is that the tvp5150 i2c module uses v4l2_async, but
the em28xx driver does not since it predates v4l2_async.

In that corner case sd->asc_list is empty, so
v4l2_async_unregister_subdev() never calls v4l2_device_unregister_subdev().

Modify the code so that, if sd->asc_list is empty,
v4l2_device_unregister_subdev() is still called.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service
Action: Update Kernel
AI Analysis

Impact

The bug arises in the v4l2_async subsystem when an em28xx USB device that uses the tvp5150 I2C driver is disconnected. Because the em28xx driver does not support v4l2_async, an empty asc_list remains. Consequently, v4l2_async_unregister_subdev never calls v4l2_device_unregister_subdev, causing the driver to attempt to unregister a sub‑device that has already been removed. This sequence leads to a kernel crash and a local denial of service on the affected system.

Affected Systems

Vendor: Linux. The affected product is the Linux kernel; any version that has not yet incorporated the described fix is potentially vulnerable. The issue was observed with the em28xx USB driver and tvp5150 I2C module. The CPE string indicates that the problem is relevant to all Linux kernel releases until the mitigation is applied.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack scenario inferred from the description requires the attacker to cause the device to be detached or to trigger the unregister path, which typically demands local or privileged access to the USB subsystem. Based on the explanation, the most plausible vector is local with physical or administrative control of the target machine, making a network‑based remote exploit unlikely.

Generated by OpenCVE AI on September 19, 2026 at 07:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Linux kernel that contains the v4l2_async unregister fix referenced in the provided links.
  • If a kernel upgrade is not feasible, apply the patch that calls v4l2_device_unregister_subdev when asc_list is empty and rebuild the affected modules.
  • Disable automatic device removal or re‑enumeration for the em28xx driver until the patch or upgraded kernel is in place.

Generated by OpenCVE AI on September 19, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: Unregister sub-device if asc_list is empty When my em28xx USB device that uses the i2c tvp5150 driver is disconnected, it crashes. The cause is that the tvp5150 i2c module uses v4l2_async, but the em28xx driver does not since it predates v4l2_async. In that corner case sd->asc_list is empty, so v4l2_async_unregister_subdev() never calls v4l2_device_unregister_subdev(). Modify the code so that, if sd->asc_list is empty, v4l2_device_unregister_subdev() is still called.
Title media: v4l2-async: Unregister sub-device if asc_list is empty
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:13.738Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.357

Modified: 2026-09-17T17:18:04.357

Link: CVE-2026-93101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses