media: pwc: Drain fill_buf on start_streaming() failure
Summary
| CVE | CVE-2026-68217 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:09 UTC |
| Updated | 2026-08-10 13:20:09 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Drain fill_buf on start_streaming() failure
pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:
start_streaming()
pwc_isoc_init()
usb_submit_urb(urbs[0], GFP_KERNEL)
pwc_isoc_handler(urbs[0])
pdev->fill_buf =
pwc_get_next_fill_buf(pdev)
usb_submit_urb(urbs[i>0], ..) -> fails
pwc_isoc_cleanup(pdev) /* kills URBs */
return ret;
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).
stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.
Issue identified by automated review of the INV-003 series at
https://sashiko.dev/ |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 885fe18f5542fe283a17f70583383c6cadcba1c3 a56e7641e09bd80b976e944ae759109b86fd5b38 git |
Not specified |
| CNA |
Linux |
Linux |
affected 885fe18f5542fe283a17f70583383c6cadcba1c3 acc789b2173070638cad89c2b61d33ed338be0dd git |
Not specified |
| CNA |
Linux |
Linux |
affected 885fe18f5542fe283a17f70583383c6cadcba1c3 9afd605dcd96c7a45f338eded1de16679b30e1df git |
Not specified |
| CNA |
Linux |
Linux |
affected 885fe18f5542fe283a17f70583383c6cadcba1c3 5d4812668b03f823b5044789d6aa77fe56b42587 git |
Not specified |
| CNA |
Linux |
Linux |
affected 885fe18f5542fe283a17f70583383c6cadcba1c3 906e410dcffbbd99fb4081abab817a830033aa28 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.1 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.1 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.