CVE-2026-68223
CVE CVE-2026-68223EUVD EUVD-2026-55324Published 2026-08-10T12:00:44.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open() function previously jumped directly to err_m2m_release when vdec_init_ctrls() failed, skipping release of the m2m context. This caused a resource leak. Fix it by introducing a proper err_m2m_ctx_release label that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before releasing the m2m device. This was identified via kmemleak: unreferenced object 0xffff0000205d6878 (size 8): comm "v4l_id", pid 5289, jiffies 4294938580 hex dump (first 8 bytes): 40 d2 49 18 00 00 ff ff @.I..... backtrace (crc d3204599): kmemleak_alloc+0xc8/0xf0 __kvmalloc_node_noprof+0x60c/0x850 v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev] vdec_open+0x1f4/0x788 [meson_vdec] v4l2_open+0x144/0x460 [videodev] chrdev_open+0x1ac/0x500 do_dentry_open+0x3f0/0xfe8 vfs_open+0x68/0x320 do_open+0x2d8/0x9a8 path_openat+0x1d0/0x4f0 do_filp_open+0x190/0x380 do_sys_openat2+0xf8/0x1b0 __arm64_sys_openat+0x13c/0x1e8 invoke_syscall+0xdc/0x268 el0_svc_common.constprop.0+0x178/0x258 do_el0_svc+0x4c/0x70
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 3e7f51bd96077acad6acd7b45668f65b44233c4e <c6cd08a71a630f19b10c318e76e3c56e1dd10e00; 3e7f51bd96077acad6acd7b45668f65b44233c4e <940f161f734b25f175a95d2684c2021f6323693a; patch: 6.12.101; patch: 7.1.6; patch: 6.6.148; 5.3; 3e7f51bd96077acad6acd7b45668f65b44233c4e <1391b75bf0119b5d37f1c1c3078d452a01967f9b; 3e7f51bd96077acad6acd7b45668f65b44233c4e <99f3527bd1a27ff798d59177ed045b0dd87deaef; patch: 0; patch: 6.18.42; 3e7f51bd96077acad6acd7b45668f65b44233c4e <2cf0171ad594860e31723c671e37824ce12c01ea; patch: 7.2-rc1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.