{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68227","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.376Z","datePublished":"2026-08-10T12:00:49.821Z","dateUpdated":"2026-08-19T16:31:59.091Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:31:59.091Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: fix devres lifetime\n\nUSB drivers bind to USB interfaces and any device managed resources\nshould have their lifetime tied to the interface rather than parent USB\ndevice. This avoids issues like memory leaks when drivers are unbound\nwithout their devices being physically disconnected (e.g. on probe\ndeferral or configuration changes).\n\nFix the driver state lifetime so that it is released on driver unbind."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/usb/cx231xx/cx231xx-cards.c"],"versions":[{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"1770fc4e2b47b1185e6f688d4012bc91f7543854","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"c07f535bcdd3f956d4c32085535368f46ba99ba0","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"a373f1a5137e96549a795e7fb9efb5de0ae1d065","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"c5ccb01eb1107acb6aab8ce8fe5a523f215c837e","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"f468b7ee5d6332b01e6c538179a4c720e6dae93b","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"e797e252bfb3d0d4b3d38e4faef817e05869c240","status":"affected","versionType":"git"},{"version":"184a82784d50ad82aadc3917a3bdd8314a0e9b9b","lessThan":"7d6358ab02866e5b7ed8d3a00805297617bbb0ec","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/usb/cx231xx/cx231xx-cards.c"],"versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1770fc4e2b47b1185e6f688d4012bc91f7543854"},{"url":"https://git.kernel.org/stable/c/c07f535bcdd3f956d4c32085535368f46ba99ba0"},{"url":"https://git.kernel.org/stable/c/0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f"},{"url":"https://git.kernel.org/stable/c/a373f1a5137e96549a795e7fb9efb5de0ae1d065"},{"url":"https://git.kernel.org/stable/c/c5ccb01eb1107acb6aab8ce8fe5a523f215c837e"},{"url":"https://git.kernel.org/stable/c/f468b7ee5d6332b01e6c538179a4c720e6dae93b"},{"url":"https://git.kernel.org/stable/c/e797e252bfb3d0d4b3d38e4faef817e05869c240"},{"url":"https://git.kernel.org/stable/c/7d6358ab02866e5b7ed8d3a00805297617bbb0ec"}],"title":"media: cx231xx: fix devres lifetime","x_generator":{"engine":"bippy-1.2.0"}}}}