CVE-2026-89872

Source
https://cve.org/CVERecord?id=CVE-2026-89872
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89872.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89872
Downstream
Published
2026-09-16T10:31:40Z
Modified
2026-09-18T03:48:33Z
Summary
media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
Details

In the Linux kernel, the following vulnerability has been resolved:

media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link

In v4l2_fwnode_parse_link(), the remote endpoint fwnode reference is acquired using fwnode_graph_get_remote_endpoint(). This reference is properly released in the error paths, but it is leaked on the success path.

Add the missing fwnode_handle_put() before returning 0 to prevent the reference leak.

[Sakari Ailus: Fix subject prefix and coding style a little.]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89872.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca50c197bd9610ea984cfc0dc6855f183cbb46f8
Fixed
c9b5238d173ee9b94dcaa2b34244ea89c8024feb
Fixed
ccd8d1d80afab8b492a583ae81bfd295835bab2f
Fixed
d92dc4692834e04bc0ef1d0908589852050d1a66
Fixed
ef609b3ce456f021320fee2fb7e45094a3ccf232
Fixed
578c4bfa28bf21458ecdde2fd3fc429475f34c10
Fixed
3ced388b7908270529e5aa6d221840114b6c33bc
Fixed
881aafb139520570fd3390bf9938d7098b7fbb99
Fixed
a6e86efd7f85e519bf48417f41923f8bd51f1597

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89872.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89872.json"