CVE-2026-68203

Source
https://cve.org/CVERecord?id=CVE-2026-68203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68203
Downstream
Published
2026-08-10T12:00:22.319Z
Modified
2026-08-12T04:18:46.489483948Z
Summary
media: vivid: fix cleanup bugs in vivid_init()
Details

In the Linux kernel, the following vulnerability has been resolved:

media: vivid: fix cleanup bugs in vivid_init()

When platformdeviceregister() fails in vividinit(), the embedded struct device in vividpdev has already been initialized by deviceinitialize(), but the failure path jumps to freeoutput_strings without dropping the device reference for the current platform device:

vividinit() -> platformdeviceregister(&vividpdev) -> deviceinitialize(&vividpdev.dev) -> setuppdevdmamasks(&vividpdev) -> platformdeviceadd(&vivid_pdev)

This leads to a reference leak when platformdeviceregister() fails. Fix this by calling platformdeviceput() before jumping to the common cleanup path.

Also, the unregdriver label incorrectly calls platformdriverregister() instead of platformdriver_unregister(), which breaks cleanup when workqueue creation fails after successful driver registration. Fix that as well.

The reference leak was identified by a static analysis tool I developed and confirmed by manual review. The incorrect cleanup call was found during code inspection.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68203.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f46d740fb0258982f00ffdbddc6486e674edafb5
Fixed
4385092a86b94e1f332db35a3766108978c0722f
Fixed
1349af7f87df57940619f5b87990b799dac9ed8a
Fixed
6d51ad8f1c50c50d1abcc97fd243179967184c6a
Fixed
a07c179a92e949172ca52f6d4a13202ea88cd4b7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68203.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68203.json"