CVE-2026-68228

Source
https://cve.org/CVERecord?id=CVE-2026-68228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68228
Downstream
Published
2026-08-10T12:00:50.892Z
Modified
2026-08-18T03:30:56.879791156Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: chips-media: wave5: Move src_buf Removal to finish_encode
Details

In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Move srcbuf Removal to finishencode

During encoder processing, there is a case where the IRQ response could return the buffer back to userspace via v4l2m2mbufdone call. In this time, userspace could queue up this same buffer before startencode removes the index from the ready queue. This would then lead to a case where the buffer in the ready queue could be a self loop due to the WRITE_ONCE(prev->next, new) call in _listadd.

When _listdel is finally called, the loop is already made so nothing points back to ready queue list head and pointers are poisoned.

A buffer should not be marked as DONE before the buffer is removed from m2m ready queue. Move removal entirely to finish_encode.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68228.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9707a6254a8a6b978bde811a44fe07d86c229d1c
Fixed
1ee2b2b189ddc7b23c8eee1145de42b8bd19fb06
Fixed
f24ca8b53fe15db40957bdaa40c9aa68e1557bbe
Fixed
d681227ce43bfd74b6eb69beecd9b0bec1fd8b48
Fixed
b20157147089a9c16a38c7810e2fe6f2df8e3277

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68228.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68228.json"