media: em28xx: fix use-after-free in em28xx_v4l2_open()

Summary

CVECVE-2026-31583
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-04-24 15:16:33 UTC
Updated2026-06-01 17:16:49 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct and set dev->v4l2 to NULL under dev->lock. This race leads to two issues: - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler, since the video_device is embedded in the freed em28xx_v4l2 struct. - NULL pointer dereference in em28xx_resolution_set() when accessing v4l2->norm, since dev->v4l2 has been set to NULL. Fix this by moving the mutex_lock() before the dev->v4l2 read and adding a NULL check for dev->v4l2 under the lock.

Risk And Classification

Primary CVSS: v3.1 7.8 HIGH from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.000180000 probability, percentile 0.048130000 (date 2026-04-27)

Problem Types: CWE-416

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 3c0283a59e36e3707c4a81f4952e362d31f876b8 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 2cbf81f76842e46bdf25823c70e1db4044a65678 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 38a327221f7f765e7d853b7bafe47e342441ec85 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e b5d141ea15f173f15b9f0a72965902f3428c0d92 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 5fb2940327722b4684d2f964b54c1c90aa277324 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 871b8ea8ef39a6c253594649f4339378fad3d0dd git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e 6b9e66437cc6123ddedac141e1b8b6fcf57d2972 git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e dd2b888e08d3b3d6aacd65d76cd44fac11da750f git Not specified
CNA Linux Linux affected 8139a4d583abad45eb987b5a99b3281b6d435b7e a66485a934c7187ae8e36517d40615fa2e961cff git Not specified
CNA Linux Linux affected 3.16 Not specified
CNA Linux Linux unaffected 3.16 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.136 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.83 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.24 6.18.* semver Not specified
CNA Linux Linux unaffected 6.19.14 6.19.* semver Not specified
CNA Linux Linux unaffected 7.0.1 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/a66485a934c7187ae8e36517d40615fa2e961cff 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/dd2b888e08d3b3d6aacd65d76cd44fac11da750f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/b5d141ea15f173f15b9f0a72965902f3428c0d92 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/871b8ea8ef39a6c253594649f4339378fad3d0dd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/6b9e66437cc6123ddedac141e1b8b6fcf57d2972 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/5fb2940327722b4684d2f964b54c1c90aa277324 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/38a327221f7f765e7d853b7bafe47e342441ec85 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3c0283a59e36e3707c4a81f4952e362d31f876b8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2cbf81f76842e46bdf25823c70e1db4044a65678 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report