CVE-2026-89901

Source
https://cve.org/CVERecord?id=CVE-2026-89901
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89901.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89901
Downstream
Published
2026-09-16T10:32:00Z
Modified
2026-09-17T03:47:19Z
Summary
media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref
Details

In the Linux kernel, the following vulnerability has been resolved:

media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref

airspy_disconnect() clears s->udev under v4l2_lock, but airspy_stop_streaming() unconditionally calls airspy_ctrl_msg() and airspy_free_stream_bufs() afterwards. If a streaming user closes the device after disconnect, stop_streaming() runs and dereferences the NULL s->udev:

airspy_stop_streaming() airspy_ctrl_msg(s, CMD_RECEIVER_MODE, 0, 0, NULL, 0) usb_sndctrlpipe(s->udev, 0) /* NULL deref / airspy_free_stream_bufs(s) usb_free_coherent(s->udev, ...) / NULL deref */

The airspy driver uses vb2_fop_release() in its file_operations, so replace video_unregister_device(&s->vdev) with vb2_video_unregister_device(&s->vdev) and move it before clearing s->udev. vb2_video_unregister_device() releases the vb2 queue, which synchronously runs airspy_stop_streaming() if streaming is active, so the URBs, coherent DMA stream buffers and the hardware stop control message all execute while s->udev is still valid.

vb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock) internally, and stop_streaming() locks v4l2_lock, so the previous outer mutex_lock(&s->vb_queue_lock) / mutex_lock(&s->v4l2_lock) pair around the unregister sequence would self-deadlock and has been removed. A short v4l2_lock critical section around s->udev = NULL remains so any ioctl path that still holds the file descriptor sees coherent state.

Issue identified by automated review of the INV-003 series at https://sashiko.dev/

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89901.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
634fe5033951b80ef4b98d8f047cb1083d29170d
Fixed
c9081e2655188d2d134a741aec837dc70439d505
Fixed
75089cea32e5055773bd13116236d08fdc98678a
Fixed
155d0378ae0d6305cc4840583a6b42d2d0595bff
Fixed
6e4ea90fdc6608cd5fac342e146ab6ae15d430bc
Fixed
a9a8c37ddda9fa3687b142be9098e1c37b8faf35
Fixed
297fee023f46d771a844520675692ea089d80d9d
Fixed
c6749ac8f59cc80eb1b2d52f167fdf13e12655cc
Fixed
2f378dc45e685fc825d2dd08e7864666d6fcc009

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89901.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89901.json"