CVE-2026-68216

Source
https://cve.org/CVERecord?id=CVE-2026-68216
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68216.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68216
Downstream
Published
2026-08-10T12:00:35.592Z
Modified
2026-08-12T04:18:46.616204945Z
Summary
media: pwc: Return queued buffers on start_streaming() failure
Details

In the Linux kernel, the following vulnerability has been resolved:

media: pwc: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via bufqueue() before calling startstreaming(). If startstreaming() returns an error without first returning those buffers via vb2bufferdone(), vb2startstreaming() fires WARNON(ownedbydrv_count) and the queued buffers leak.

pwc's startstreaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutexlockinterruptible() was interrupted by a signal. Call the existing pwccleanupqueuedbufs() helper with VB2BUFSTATEQUEUED before returning (matching the state already used by the pwcisoc_init() error path in the same function).

This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68216.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478
Fixed
f2f9fcacd81953dde6cb86312ab13ca13e689664
Fixed
5d7cc2634c3843a1414a0f6407aa17f1f91dee60
Fixed
cb16b79a2be2cec9c3ebe4147490817c4d8b1de3
Fixed
a4f8f629983f643333e49df90557805469bcbb25
Fixed
975b2ee20e569d47821e4f6c9761b4664d48a6a4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68216.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.5.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68216.json"