PT-2026-90238 · Linux · Linux

CVE-2026-89522

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
media: staging/ipu7: fix async notifier UAF on probe error path
isys register devices() registers the V4L2 async notifier via isys notifier init(). If a subsequent probe step such as isys fw log init() fails, isys probe() jumps to the out cleanup label which only calls isys unregister devices(). That helper tears down the video devices, subdevices, V4L2 device and media device, but never unregisters or cleans up the async notifier.
As a result the notifier stays chained in the global notifier list while the enclosing struct ipu7 isys is freed by devres, leading to list corruption and a use-after-free the next time the list is walked.
The remove path already does the right thing by calling isys notifier cleanup() before isys unregister devices(). Mirror that on the probe error path so the notifier is unregistered and cleaned up before the device is torn down.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89522

Affected Products

Linux