CVE-2026-89880

Source
https://cve.org/CVERecord?id=CVE-2026-89880
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89880.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89880
Downstream
Published
2026-09-16T10:31:46Z
Modified
2026-09-18T03:48:33Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
Details

In the Linux kernel, the following vulnerability has been resolved:

media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure

rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(), rtl2832_sdr_alloc_urbs() and rtl2832_sdr_submit_urbs() in sequence and shares a single err: label that only unlocks the mutex and returns. When alloc_urbs() succeeds but submit_urbs() fails, or when alloc_urbs() itself returns -ENOMEM after alloc_stream_bufs() has already succeeded, the URBs and/or the coherent DMA stream buffers stay allocated while streaming reports failure to vb2. Two latent defects follow on the next VIDIOC_STREAMON:

  1. rtl2832_sdr_alloc_stream_bufs() unconditionally resets dev->buf_num to 0 and overwrites dev->buf_list[]/dev->dma_addr[], permanently leaking the coherent DMA memory allocated by the previous attempt.

  2. rtl2832_sdr_alloc_urbs() never resets dev->urbs_initialized and only increments it. After a second successful pass urbs_initialized can exceed MAX_BULK_BUFS, so the subsequent rtl2832_sdr_free_urbs() walks from urbs_initialized - 1 down to 0 and reads past the end of dev->urb_list[], passing garbage pointers to usb_free_urb().

Mirror the teardown that stop_streaming() already performs: on the error path call rtl2832_sdr_free_urbs() and rtl2832_sdr_free_stream_bufs() before unlocking. Both helpers are idempotent (free_urbs kills and zeros urbs_initialized; free_stream_bufs is gated on URB_BUF and clears the buf_num counter), so partial-failure paths and the no-allocation paths remain safe.

Issue identified by automated review of the INV-003 series at https://sashiko.dev/

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89880.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
771138920eafa399f68d3492c8a75dfeea23474b
Fixed
f14a713a36a5c87568430e9770896f2a8f5bbbb7
Fixed
c819dea3a433ae790b829443fdcc1715d1586560
Fixed
0337ab0759285076a3f9dcfcc40906e69ab519b3
Fixed
c91e8ae2b39c6da81f26f2c9877d3fd33a4465ce
Fixed
8bcf11a239eac4e224ad856277de9a36c91b1711
Fixed
26a2a985bbeee3eaa6f80ff7de732161a171ec9f
Fixed
ac02b2c56ccef0788cea9b86990a8f349a3fc6d8
Fixed
fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89880.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89880.json"