CVE-2026-68212

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: saa7134: Fix a possible memory leak in saa7134_video_init1<br /> <br /> In saa7134_video_init1(), the return value of the first<br /> saa7134_pgtable_alloc() is not checked. If it fails, the function<br /> continues as if successful, leaving the driver with an invalid page<br /> table. Additionally, if vb2_queue_init() for the VBI queue fails after<br /> the video queue page table has been allocated, the allocated memory is<br /> not freed before returning. The second saa7134_pgtable_alloc() also<br /> lacks a return value check. Errors occur during device probing before<br /> the device is fully registered, the normal cleanup path in<br /> saa7134_finidev() is not executed, leading to memory leaks and<br /> potential use of uninitialized DMA resources.<br /> <br /> Check the return value of both saa7134_pgtable_alloc() calls and<br /> propagate errors. On failure of any later step, free allocated page<br /> tables to avoid memory leaks. Ensure control handlers are also<br /> released on error to prevent further resource leakage.<br /> <br /> Found by code review.

Impact