media: mtk-jpeg: cancel workqueue on release for supported platforms only

Summary

CVECVE-2026-64358
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:18 UTC
Updated2026-07-25 10:17:18 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: cancel workqueue on release for supported platforms only Since a recent fix the mtk_jpeg_release function cancels any pending or running work present in the driver workqueue using cancel_work_sync function. Currently, only the multicore based variants use this workqueue and they have the jpeg_worker platform data field initialized with a workqueue callback function. For the others, this field value remain NULL by default. The cancel_work_sync function is unconditionally called in mtk_jpeg_release function, even for the variants that do not use the workqueue. This call generates a WARN_ON print in __flush_work because the workqueue callback function presence check fails in __flush_work function (used by cancel_work_sync). So, to avoid these warnings, call cancel_work_sync only if a workqueue callback is defined in platform data.

Risk And Classification

EPSS: 0.001680000 probability, percentile 0.064580000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2209fdae5c2f615930c9af1379c1cfca199ec5d8 0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9 git Not specified
CNA Linux Linux affected 0498b27a1542021d90269d58347501d4c3ccd84e ac0774961a6ea174a71d4ffa39966edafbf7662d git Not specified
CNA Linux Linux affected 26506a30e0e26d612f82a7bf0e395626968a44e6 973408ceab14555a8548b97c8cc7b54208c3f251 git Not specified
CNA Linux Linux affected 34c519feef3e4fcff1078dc8bdb25fbbbd10303f 4c4b4af4a9f278da096f0dbdb6b59594701d29bf git Not specified
CNA Linux Linux affected 34c519feef3e4fcff1078dc8bdb25fbbbd10303f b1845a227fda37b2fe5327df3ca0015d7e290235 git Not specified
CNA Linux Linux affected e78c39f720679fcf3a2eacd82725ec3ea2648301 git Not specified
CNA Linux Linux affected 6.6.140 6.6.145 semver Not specified
CNA Linux Linux affected 6.12.86 6.12.96 semver Not specified
CNA Linux Linux affected 6.18.27 6.18.39 semver Not specified
CNA Linux Linux affected 7.0.4 7.1 semver Not specified
CNA Linux Linux affected 7.1 Not specified
CNA Linux Linux unaffected 7.1 semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4c4b4af4a9f278da096f0dbdb6b59594701d29bf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/973408ceab14555a8548b97c8cc7b54208c3f251 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ac0774961a6ea174a71d4ffa39966edafbf7662d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b1845a227fda37b2fe5327df3ca0015d7e290235 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report