CVE-2026-89896

Source
https://cve.org/CVERecord?id=CVE-2026-89896
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89896.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89896
Downstream
Published
2026-09-16T10:31:57Z
Modified
2026-09-18T03:48:33Z
Summary
media: cedrus: fix memory leak in cedrus_init_ctrls()
Details

In the Linux kernel, the following vulnerability has been resolved:

media: cedrus: fix memory leak in cedrus_init_ctrls()

In cedrus_init_ctrls(), the V4L2 control handler is initialized before allocating memory for ctx->ctrls. If this allocation fails, the function returns -ENOMEM without freeing the previously allocated handler resources, leading to a memory leak.

Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation failure path.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an Allwinner SoC or board with a Cedrus VPU available to test with, no runtime testing was able to be performed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89896.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1
Fixed
6fabacc3b79a528450aef4c32464da2ec681049e
Fixed
729a1ffab968b3c493f61d1cd683f5bafec500ea
Fixed
ce5693b6e3a693fcdc3800af309363f6250104c8
Fixed
22441be29ec27c693f40c1ef499093275ef529d1
Fixed
79fd0b0161506fc9507bf7a6fe4c975a857a5be8
Fixed
f78cf36cabf911da348ea80e4e9f430d74f6905c
Fixed
81aa608ac3a56cdd4aab0bd12442ed529a24ba31
Fixed
9df2fbe563194da1967a5db083442186c1323efe

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89896.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89896.json"