{"api_version":"1","generated_at":"2026-09-12T11:51:21+00:00","cve":"CVE-2026-68209","urls":{"html":"https://cve.report/CVE-2026-68209","api":"https://cve.report/api/cve/CVE-2026-68209.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68209","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68209"},"summary":{"title":"media: sun4i-csi: Return queued buffers on start_streaming() failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed.  The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:08","updated_at":"2026-08-19 17:20:36"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54","name":"https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331","name":"https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309","name":"https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f","name":"https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82","name":"https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a","name":"https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d","name":"https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7","name":"https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68209","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68209","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 29fce7bcb3b959f6d4fdcdff7d26330152fdf98d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 7c2c30e282745a83d332c3cf92d1c0bcc491ac54 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 4872161e6fbe4e1783daea8bff79caddfae0fb82 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 a8abecc638a7feb20b78fabd563b05e30c071331 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 b5184b3f0e9d4cc47059ba1138c9a73d43d2493f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 668face37fdb6b6900645dc8777195498541c9a7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 577bbf23b758848f0c4a50d346460b690c753024 bbba3e260a62810a717b4442a3bb96d0ec0f6309 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.4 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.265 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.216 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.183 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.148 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68209","cve":"CVE-2026-68209","epss":"0.001750000","percentile":"0.073360000","score_date":"2026-08-19","updated_at":"2026-08-20 00:13:09"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"29fce7bcb3b959f6d4fdcdff7d26330152fdf98d","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"7c2c30e282745a83d332c3cf92d1c0bcc491ac54","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"4872161e6fbe4e1783daea8bff79caddfae0fb82","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"a8abecc638a7feb20b78fabd563b05e30c071331","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"b5184b3f0e9d4cc47059ba1138c9a73d43d2493f","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"668face37fdb6b6900645dc8777195498541c9a7","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"},{"lessThan":"bbba3e260a62810a717b4442a3bb96d0ec0f6309","status":"affected","version":"577bbf23b758848f0c4a50d346460b690c753024","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.4"},{"lessThan":"5.4","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.265","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.216","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.183","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.148","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.265","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.216","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.183","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.148","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"5.4","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed.  The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only through local V4L2 ioctls (VIDIOC_S_FMT, VIDIOC_REQBUFS, VIDIOC_QBUF, VIDIOC_STREAMON) on the sun4i-csi /dev/videoN character device. There is no network, adjacent-network, or remote data path into sun4i_csi_start_streaming().\nAC:L - The attacker deterministically drives the sequence itself: configure the capture format, queue buffers, then issue STREAMON so the driver returns an error after vb2 has already handed the buffers over. No race, timing window, or memory layout outside the attacker's control is involved, and the sequence can be retried without limit.\nPR:L - sun4i_csi_open() and the entire queue/streamon path perform no capability checks; only an open file descriptor on the video node is needed, which udev grants to the active local user via the video group and 70-uaccess.rules (or the Android CAMERA context). That is ordinary unprivileged local access, not root.\nUI:N - The attacker performs the whole open/S_FMT/QBUF/STREAMON/REQBUFS sequence inside its own process. No victim action, cooperation, or pre-existing session state is required.\nS:U - The damage is confined to kernel heap and sun4i-csi driver state within the same OS security authority. Nothing crosses a hypervisor, IOMMU, or sandbox boundary.\nC:H - Buffers stay linked on csi->buf_list after vb2 force-reclaims them, and the list head is only initialized once at probe. A later REQBUFS(0) or close frees those vb2 buffers while the driver still holds pointers, so sun4i_csi_buffer_fill_all()/return_all_buffers() read through freed slab objects the attacker can reclaim and shape, disclosing kernel heap contents.\nI:H - The stale list linkage yields list_add_tail()/list_del() operations on freed nodes, giving a write-what-where style list-corruption primitive, and the DMA fill path writes buffer addresses through the dangling entries. Under conservative memory-corruption scoring this is high integrity impact.\nA:H - The immediate effect is the WARN_ON(owned_by_drv_count) splat in vb2_start_streaming(), which panics on panic_on_warn systems, and the resulting dangling buf_list produces use-after-free oopses or slab corruption on the next streaming attempt or buffer release."}]}],"providerMetadata":{"dateUpdated":"2026-08-19T16:31:31.902Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d"},{"url":"https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54"},{"url":"https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a"},{"url":"https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82"},{"url":"https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331"},{"url":"https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f"},{"url":"https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7"},{"url":"https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"}],"title":"media: sun4i-csi: Return queued buffers on start_streaming() failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68209","datePublished":"2026-08-10T12:00:28.245Z","dateReserved":"2026-07-30T09:28:09.374Z","dateUpdated":"2026-08-19T16:31:31.902Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:08","lastModifiedDate":"2026-08-19 17:20:36","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68209","Ordinal":"1","Title":"media: sun4i-csi: Return queued buffers on start_streaming() fai","CVE":"CVE-2026-68209","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68209","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed.  The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","Type":"Description","Title":"media: sun4i-csi: Return queued buffers on start_streaming() fai"}]}}}