PT-2026-94868 · Linux · Linux Kernel
CVE-2026-93070
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A double-free issue exists in the
ipu6 media component. The function ipu6 bus initialize device() stores the isys/psys pdata pointer in struct ipu6 bus device and initializes the auxiliary device. During error unwinding, the isys and psys initialization paths call put device() upon MMU initialization failure, and ipu6 bus add device() calls auxiliary device uninit() if auxiliary device add() fails. Both scenarios trigger the bus release callback, which frees the bus device and adev->pdata. If the caller also performs a manual kfree(pdata), the same object is released a second time.Recommendations
Remove manual
pdata frees after the auxiliary device has been initialized.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel