Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68205

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()<br /> <br /> The v4l2 helper v4l2_async_register_subdev_sensor() calls<br /> v4l2_async_register_subdev(), which is a macro that expands to<br /> __v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded<br /> inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module<br /> rather than the sensor driver module that originally set sd-&gt;owner. When<br /> v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then<br /> overwrites the sensor driver&amp;#39;s owner with NULL.<br /> <br /> This causes the problem that the sensor module&amp;#39;s reference count is never<br /> incremented during async registration, so the module can be removed while<br /> the subdevice is still in use by a notifier (e.g., a CSI-2 receiver<br /> bridge driver).<br /> <br /> Fix this by renaming v4l2_async_register_subdev_sensor() to<br /> __v4l2_async_register_subdev_sensor() with an added explicit module<br /> argument and introducing a wrapper macro:<br /> #define v4l2_async_register_subdev_sensor(sd) \<br /> __v4l2_async_register_subdev_sensor(sd, THIS_MODULE)<br /> <br /> This ensures the sensor driver module is properly referenced even when<br /> the sensor driver does not init the owner field before calling<br /> v4l2_async_register_subdev_sensor() and prevents premature module removal.

Impacto