CVE-2026-68209 (GCVE-0-2026-68209)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: sun4i-csi: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
sun4i_csi_start_streaming() returned -EINVAL when no matching CSI
format could be found, before any setup (scratch buffer allocation,
pipeline start) had been performed. The remaining error paths already
converge on the err_clear_dma_queue label, which calls
return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump
to that label directly: the intermediate err_disable_device /
err_disable_pipeline / err_free_scratch_buffer labels are skipped,
which is correct because nothing they would undo has happened yet.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "4872161e6fbe4e1783daea8bff79caddfae0fb82",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "a8abecc638a7feb20b78fabd563b05e30c071331",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "668face37fdb6b6900645dc8777195498541c9a7",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed. The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi-\u003eqlock. Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local V4L2 ioctls (VIDIOC_S_FMT, VIDIOC_REQBUFS, VIDIOC_QBUF, VIDIOC_STREAMON) on the sun4i-csi /dev/videoN character device. There is no network, adjacent-network, or remote data path into sun4i_csi_start_streaming().\nAC:L - The attacker deterministically drives the sequence itself: configure the capture format, queue buffers, then issue STREAMON so the driver returns an error after vb2 has already handed the buffers over. No race, timing window, or memory layout outside the attacker\u0027s control is involved, and the sequence can be retried without limit.\nPR:L - sun4i_csi_open() and the entire queue/streamon path perform no capability checks; only an open file descriptor on the video node is needed, which udev grants to the active local user via the video group and 70-uaccess.rules (or the Android CAMERA context). That is ordinary unprivileged local access, not root.\nUI:N - The attacker performs the whole open/S_FMT/QBUF/STREAMON/REQBUFS sequence inside its own process. No victim action, cooperation, or pre-existing session state is required.\nS:U - The damage is confined to kernel heap and sun4i-csi driver state within the same OS security authority. Nothing crosses a hypervisor, IOMMU, or sandbox boundary.\nC:H - Buffers stay linked on csi-\u003ebuf_list after vb2 force-reclaims them, and the list head is only initialized once at probe. A later REQBUFS(0) or close frees those vb2 buffers while the driver still holds pointers, so sun4i_csi_buffer_fill_all()/return_all_buffers() read through freed slab objects the attacker can reclaim and shape, disclosing kernel heap contents.\nI:H - The stale list linkage yields list_add_tail()/list_del() operations on freed nodes, giving a write-what-where style list-corruption primitive, and the DMA fill path writes buffer addresses through the dangling entries. Under conservative memory-corruption scoring this is high integrity impact.\nA:H - The immediate effect is the WARN_ON(owned_by_drv_count) splat in vb2_start_streaming(), which panics on panic_on_warn systems, and the resulting dangling buf_list produces use-after-free oopses or slab corruption on the next streaming attempt or buffer release."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:31.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d"
},
{
"url": "https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54"
},
{
"url": "https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a"
},
{
"url": "https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82"
},
{
"url": "https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331"
},
{
"url": "https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f"
},
{
"url": "https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7"
},
{
"url": "https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"
}
],
"title": "media: sun4i-csi: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68209",
"datePublished": "2026-08-10T12:00:28.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:31.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…