CVE-2026-89741
CVE CVE-2026-89741EUVD EUVD-2026-76653Published 2026-09-11T19:46:47.000ZLast changed 2026-09-14T12:02:24.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-dev: fix error handling in __video_register_device()" This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a. The intentions of that patch were good, but it doesn't work. The idea is that if device_register fails, you have to do a put_device to let the ref counter release resources. However, the V4L2 API says that if video_register_device() fails, then you have to call video_device_release(), which kfree()s the video_device struct. But the put_device() will already have freed the struct, so you end up in a double-free scenario. There is not really a good way of fixing this without breaking video_register_device() into two parts, one that initializes everything, and one that does the actual device_register, and then converting all V4L2 drivers to this new model. That is a massive job, and it is very unlikely that device_register will fail. So rather than ending up in a double-free scenario, just revert this patch, and in that case we'll have a small memory leak. Which is a lot more robust.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2429bb9fad88c8fa84c4956b0a21cf5afe5e92b7 <712ca1cf756de2557a116e0df55791bac0c9f99e; ee141706e701356dda41c6fed9ee18bf427c28e3; ae7b143e05b36fc69d6571751855946cc45064c6 <2ac009a65d2385e9f0799eaf9d9694a29153a161; 2a934fdb01db6458288fc9386d3d8ceba6dd551a <ce792b94e03882108019ba996c1a7c4d4e09be2c; patch: 6.18.50; 6.16; 2a934fdb01db6458288fc9386d3d8ceba6dd551a <e7600f5cee5de14065f950807931d6e6d40fb2d7; 2a934fdb01db6458288fc9386d3d8ceba6dd551a <aad08b5f67d2a8116e1a00bce2611c1513b10bce; patch: 7.3-rc1; 8b451a9a46f2bfc510e6d5c2492df91647586184 <3de14b4f681a1b3c6d375d98d9d37a55ebb85349; patch: 6.1.188; 5.10.239 <5.10.270; patch: 5.15.221; 6.1.142 <6.1.188; patch: 0; b6be1f5633eae200af2527e9eeb7f51be5739b0f <8027f82c0f5474ed72448e160ee9778051fa1f49; 5.15.186 <5.15.221; patch: 7.2.4; 6.6.95 <6.6.157; 4451412739ed33a49b34624299394ee575116d0c; 5.4.295 <5.5; patch: 6.12.109; patch: 6.6.157; 6.15.4 <6.16; patch: 5.10.270; e5c8e62ae551e0ad2e15412aa0c57c2856d59677 <8b998c171ed875e402e1fd1c5cd619e4ca05e9c1; 6.12.35 <6.12.109
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.