PT-2026-93537 · Linux · Linux Kernel

CVE-2026-89896

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.1.2
Description A memory leak exists in the cedrus init ctrls() function. The V4L2 control handler is initialized before memory is allocated for ctx->ctrls. If the memory allocation for ctx->ctrls fails, the function returns an error without freeing the resources previously allocated for the handler.
Recommendations Update the Linux kernel to version 7.1.2 or later. As a temporary workaround, restrict the use of the Cedrus VPU driver to minimize the risk of memory exhaustion.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101565
CVE-2026-89896
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel