CVE-2026-93071

Source
https://cve.org/CVERecord?id=CVE-2026-93071
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93071.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93071
Downstream
Published
2026-09-17T16:10:55Z
Modified
2026-09-18T03:48:43Z
Summary
media: bcm2835-unicam: Fix asc leaked in error/remove path
Details

In the Linux kernel, the following vulnerability has been resolved:

media: bcm2835-unicam: Fix asc leaked in error/remove path

v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed when v4l2_async_nf_cleanup() is called.

Call v4l2_async_nf_cleanup() properly in the driver paths.

Discovered with kmemleak after rmmod:

unreferenced object 0xffff000084526b80 (size 64): comm "modprobe", pid 185, jiffies 4295013512 hex dump (first 32 bytes): 01 00 00 00 00 00 00 00 e8 0d ff bf 00 00 ff ff ................ 40 83 bc 84 00 00 ff ff 60 83 bc 84 00 00 ff ff @.......`....... backtrace (crc ac584083): [<00000000ffb081a7>] kmemleak_alloc+0x38/0x44 [<00000000d2fd9301>] __kmalloc+0x1b0/0x250 [<000000004dd5354d>] __v4l2_async_nf_add_fwnode+0x28/0x9c [<0000000067587657>] __v4l2_async_nf_add_fwnode_remote+0x3c/0x64

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93071.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
392cd78d495f36c201eb5cc425b01017d493e094
Fixed
5479372db364c80bb6bd59f640f5c31de3984bab
Fixed
2c29cd408ef86e695acb2a5d4e00fa2f5695368d
Fixed
de9be39cefda1ecd762e6a913665c01f7bb18100
Fixed
253c9659e25131b0169f718e7d094ac1aa0d9279

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93071.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93071.json"