CVE-2026-68217
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
media: pwc: Drain fill_buf on start_streaming() failure<br />
<br />
pwc_isoc_init() submits its isochronous URBs with<br />
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is<br />
submitted, its completion handler pwc_isoc_handler() can run on another<br />
CPU before the loop finishes:<br />
<br />
start_streaming()<br />
pwc_isoc_init()<br />
usb_submit_urb(urbs[0], GFP_KERNEL)<br />
pwc_isoc_handler(urbs[0])<br />
pdev->fill_buf =<br />
pwc_get_next_fill_buf(pdev)<br />
usb_submit_urb(urbs[i>0], ..) -> fails<br />
pwc_isoc_cleanup(pdev) /* kills URBs */<br />
return ret;<br />
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)<br />
<br />
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and<br />
stores it in pdev->fill_buf. The error path in start_streaming() only<br />
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is<br />
leaked. vb2_start_streaming() then triggers<br />
WARN_ON(owned_by_drv_count).<br />
<br />
stop_streaming() already handles this since commit 80b0963e1698<br />
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the<br />
teardown path but not in the start_streaming() error path. Mirror that<br />
handling on failure so start_streaming() returns with no buffer owned<br />
by the driver.<br />
<br />
Issue identified by automated review of the INV-003 series at<br />
https://sashiko.dev/
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587
- https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28
- https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d
- https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df
- https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130
- https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38
- https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd
- https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565


