PT-2026-93537 · Linux · Linux Kernel
CVE-2026-89896
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 7.1.2
Description
A memory leak exists in the
cedrus init ctrls() function. The V4L2 control handler is initialized before memory is allocated for ctx->ctrls. If the memory allocation for ctx->ctrls fails, the function returns an error without freeing the resources previously allocated for the handler.Recommendations
Update the Linux kernel to version 7.1.2 or later.
As a temporary workaround, restrict the use of the Cedrus VPU driver to minimize the risk of memory exhaustion.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel