{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89887","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.773Z","datePublished":"2026-09-16T10:31:51.195Z","dateUpdated":"2026-09-16T14:39:37.116Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:37.116Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: ov7740: fix use-after-destroy in remove\n\nThe ov7740_remove() function had a severe teardown order bug where it\ndestroyed the driver's mutex before freeing the V4L2 control handler\nwhich relies on that mutex, leading to a use-after-destroy kernel panic.\nFurthermore, the driver explicitly called v4l2_ctrl_handler_free() and\nmutex_destroy() sequentially, but then called ov7740_free_controls()\nwhich invokes both of them a second time, resulting in a double-free.\n\nThis patch fixes the issue by unregistering the subdevice first, and\nrelying exclusively on ov7740_free_controls() to safely tear down the\nmutex and control handler in the correct order."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is in ov7740_remove() for the onboard OmniVision OV7740 I2C/CSI camera sensor, reached via local I2C teardown (sysfs unbind, i2c delete_device, rmmod) and V4L2 ioctls on /dev/v4l-subdev* (V4L2_SUBDEV_FL_HAS_DEVNODE). No network, Bluetooth, or USB packet path exists.\nAC:L - ov7740_remove() deterministically mutex_destroy()s ov7740->mutex then v4l2_ctrl_handler_free() locks that same mutex and kvfree()s all v4l2_ctrl objects while the subdev is still registered. An attacker holding the node and driving teardown needs no uncontrollable race or rare debug config.\nPR:L - VIDIOC_G/S_CTRL on the subdev node have no capable() check; udev typically grants /dev/v4l-subdev* to the video group or Android camera UID on SAMA5/embedded boards shipping CONFIG_VIDEO_OV7740. Per CNA driver-removal UAF and media i2c unbind precedent this is PR:L, not init-namespace root.\nUI:N - The attacker opens the V4L2 subdev node and initiates or coordinates driver teardown themselves (unbind/rmmod/maintenance). CNA driver-removal UAFs score UI:N; no separate victim action such as mounting a filesystem is required.\nS:U - The UAF corrupts host kernel heap (struct v4l2_ctrl, v4l2_ctrl_ref, and handler buckets) within the same OS security authority. It is not a VM escape, IOMMU/DMA isolation bypass, or sandbox breakout.\nC:H - v4l2_ctrl_handler_free() kvfree()s each v4l2_ctrl while open fds still hold vfh->ctrl_handler and issue VIDIOC_G_CTRL/G_EXT_CTRLS through dangling ctrl lists. Per kernel UAF guidance this enables arbitrary kernel disclosure, so confidentiality is High.\nI:H - struct v4l2_ctrl embeds ops and type_ops function pointers; VIDIOC_S_CTRL on a sprayed freed object yields control-flow hijack. Kernel UAF guidance scores this High integrity.\nA:H - mutex_lock of the destroyed mutex and later walks of freed ctrl lists after handler_free oops or panic the kernel even when the UAF is not fully turned into a write primitive, so availability is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/i2c/ov7740.c"],"versions":[{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"9e4693436c7dcf8584002500ce4b434b79bbf9ed","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"81e9765878d3ac8ad18e3a683332b5d6bc3a0e33","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"8a02ee6c1c4e88f3a0442bd60d3c77db9a30db5e","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"7512838a19af0a284a58435292243fad21e57ff1","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"25e2505866c577db2661e4d431f0907c6ec9a3b4","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"af81f35e4f429e769b784754e1aa4d7a922470ac","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"09453b467990e8ef8fe09f45a685f9a625248d33","status":"affected","versionType":"git"},{"version":"39c5c4471b8d793daf868bd004e56ed420e89707","lessThan":"5d1b3dea5a44124bab6c14a2d71b977dabed54e7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/i2c/ov7740.c"],"versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9e4693436c7dcf8584002500ce4b434b79bbf9ed"},{"url":"https://git.kernel.org/stable/c/81e9765878d3ac8ad18e3a683332b5d6bc3a0e33"},{"url":"https://git.kernel.org/stable/c/8a02ee6c1c4e88f3a0442bd60d3c77db9a30db5e"},{"url":"https://git.kernel.org/stable/c/7512838a19af0a284a58435292243fad21e57ff1"},{"url":"https://git.kernel.org/stable/c/25e2505866c577db2661e4d431f0907c6ec9a3b4"},{"url":"https://git.kernel.org/stable/c/af81f35e4f429e769b784754e1aa4d7a922470ac"},{"url":"https://git.kernel.org/stable/c/09453b467990e8ef8fe09f45a685f9a625248d33"},{"url":"https://git.kernel.org/stable/c/5d1b3dea5a44124bab6c14a2d71b977dabed54e7"}],"title":"media: i2c: ov7740: fix use-after-destroy in remove","x_generator":{"engine":"bippy-1.2.0"}}}}