CVE-2026-80650
CVE CVE-2026-80650EUVD EUVD-2026-67526Published 2026-08-28T06:48:58.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: gc2235: fix UAF and memory leak gc2235_probe() handles its error paths incorrectly. If media_entity_pads_init() fails, gc2235_remove() is called, which tears down the subdev and frees dev, but then still falls through to atomisp_register_i2c_module(). This results in use-after-free. If atomisp_register_i2c_module() fails, the media entity and control handler are left initialized and dev is leaked. gc2235_remove() unconditionally calls media_entity_cleanup() and v4l2_ctrl_handler_free(), but these are not initialized at every error path in gc2235_probe(). Replace gc2235_remove() calls in the probe error paths with explicit unwind labels that free only the resources initialized at each point of failure, in reverse order of initialization.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux a49d25364dfb9f8a64037488a39ab1f56c5fa419 <d57e67ea48e4d095052f2b14d8dd7593621f862f; patch: 6.18.40; a49d25364dfb9f8a64037488a39ab1f56c5fa419 <628f763aee0047ff44974388d6f70f75a763026b; a49d25364dfb9f8a64037488a39ab1f56c5fa419 <fdbb8e55578b4ab647fa58827a9dd8730d7f4add; patch: 0; a49d25364dfb9f8a64037488a39ab1f56c5fa419 <f614bf0a64aa1cb7444d152a96798a6bf1d49e1f; patch: 7.2; patch: 7.1.5; patch: 6.12.97; 4.12
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.