{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89870","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.771Z","datePublished":"2026-09-16T10:31:39.271Z","dateUpdated":"2026-09-16T14:39:26.773Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:26.773Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: zoran: Avoid freeing a registered video_device twice\n\nzoran_init_video_device() installs zoran_vdev_release() as the\nvideo_device release callback through zoran_template. After\nvideo_register_device() succeeds, video_unregister_device() drops the\nregistered video_device reference and the V4L2 core eventually invokes\nthat release callback, which kfree()s the video_device.\n\nzoran_exit_video_devices() called video_unregister_device() and then\nkfree(zr->video_dev), so device teardown could free the same\nvideo_device twice.\n\nRemove the direct kfree() and clear the cached pointer after\nunregistering. The pre-registration failure path keeps its manual free\nbecause the video_device was not registered there.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The double-free is in zoran_exit_video_devices() on the ZR36057/36067 PCI MJPEG capture driver's zoran_remove() path (rmmod zr36067, PCI sysfs unbind, or hot-remove). It is reached from local driver teardown, not from network packets or a remote protocol.\nAC:L - After a successful probe, zoran_remove() always calls video_unregister_device() then kfree(zr->video_dev). With no open fds, v4l2_device_release() already kfree's via zoran_vdev_release, so the second kfree is a deterministic double-free. With an fd held, the extra kfree is a deterministic UAF. No attacker-uncontrollable race or layout is required.\nPR:L - v4l2_open() has no capable() check; udev typically grants /dev/video* to the video group or seated uaccess user on capture/surveillance hosts (e.g. AverMedia 6 Eyes). Per CNA driver-removal UAF precedent, an unprivileged local user can hold the node and spray the freed video_device while teardown proceeds; init-namespace root is not required.\nUI:N - No victim action such as mounting a filesystem is required; the attacker opens /dev/video themselves and coordinates with driver removal (unbind/rmmod/maintenance). CNA driver-removal UAFs score UI:N.\nS:U - The double-free/UAF corrupts the host kernel slab object struct video_device. Any privilege escalation remains in the same kernel; this is not a VM/IOMMU boundary bypass.\nC:H - Double-free/UAF of struct video_device lets an attacker reclaim the slab object and read leftover kernel pointers/object state via subsequent ioctl/mmap on a still-open /dev/video fd, so confidentiality is High.\nI:H - struct video_device embeds fops, ioctl_ops, and a release callback; reclaiming the freed object enables function-pointer overwrite and control-flow hijacking, so integrity is High.\nA:H - A kernel double-free of video_device causes an oops/panic on the second kfree or on use of the dangling device, so availability is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/pci/zoran/zoran_card.c"],"versions":[{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"3ad6cf27505017a6794f5f96c31218c2291e951b","status":"affected","versionType":"git"},{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"c4acac8cdc005b2d14b6cef5e215d264212857f3","status":"affected","versionType":"git"},{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"4d99d8d0d895489064783601a516bd45812fa992","status":"affected","versionType":"git"},{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"f1c4f3885df1f09bcab5296d86834d104f865e86","status":"affected","versionType":"git"},{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"672dbccf4351370dad002d3c78dbb29ca1588f22","status":"affected","versionType":"git"},{"version":"82e3a496eb56da0b9f29fdc5b63cedb3289e91de","lessThan":"0735e0b5a96761a9ce277a238e834008ad92a0a5","status":"affected","versionType":"git"},{"version":"bd01629315ffd5b63da91d0bd529a77d30e55028","status":"affected","versionType":"git"},{"version":"ff3357bffd9fb78f59762d8955afc7382a279079","status":"affected","versionType":"git"},{"version":"c1ba65100a359fe28cfe37e09e10c99f247cbf1e","status":"affected","versionType":"git"},{"version":"1e501ec38796f43e995731d1bcd4173cb1ccfce0","status":"affected","versionType":"git"},{"version":"5.10.110","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.15.33","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"5.16.19","lessThan":"5.17","status":"affected","versionType":"semver"},{"version":"5.17.2","lessThan":"5.18","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/pci/zoran/zoran_card.c"],"versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16.19"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3ad6cf27505017a6794f5f96c31218c2291e951b"},{"url":"https://git.kernel.org/stable/c/c4acac8cdc005b2d14b6cef5e215d264212857f3"},{"url":"https://git.kernel.org/stable/c/4d99d8d0d895489064783601a516bd45812fa992"},{"url":"https://git.kernel.org/stable/c/f1c4f3885df1f09bcab5296d86834d104f865e86"},{"url":"https://git.kernel.org/stable/c/672dbccf4351370dad002d3c78dbb29ca1588f22"},{"url":"https://git.kernel.org/stable/c/0735e0b5a96761a9ce277a238e834008ad92a0a5"}],"title":"media: zoran: Avoid freeing a registered video_device twice","x_generator":{"engine":"bippy-1.2.0"}}}}