{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89896","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.773Z","datePublished":"2026-09-16T10:31:57.504Z","dateUpdated":"2026-09-16T10:31:57.504Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T10:31:57.504Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cedrus: fix memory leak in cedrus_init_ctrls()\n\nIn cedrus_init_ctrls(), the V4L2 control handler is initialized before\nallocating memory for ctx->ctrls. If this allocation fails, the function\nreturns -ENOMEM without freeing the previously allocated handler\nresources, leading to a memory leak.\n\nFix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation\nfailure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nAllwinner SoC or board with a Cedrus VPU available to test with, no\nruntime testing was able to be performed."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/media/sunxi/cedrus/cedrus.c"],"versions":[{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"6fabacc3b79a528450aef4c32464da2ec681049e","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"729a1ffab968b3c493f61d1cd683f5bafec500ea","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"ce5693b6e3a693fcdc3800af309363f6250104c8","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"22441be29ec27c693f40c1ef499093275ef529d1","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"79fd0b0161506fc9507bf7a6fe4c975a857a5be8","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"f78cf36cabf911da348ea80e4e9f430d74f6905c","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"81aa608ac3a56cdd4aab0bd12442ed529a24ba31","status":"affected","versionType":"git"},{"version":"50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1","lessThan":"9df2fbe563194da1967a5db083442186c1323efe","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/media/sunxi/cedrus/cedrus.c"],"versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6fabacc3b79a528450aef4c32464da2ec681049e"},{"url":"https://git.kernel.org/stable/c/729a1ffab968b3c493f61d1cd683f5bafec500ea"},{"url":"https://git.kernel.org/stable/c/ce5693b6e3a693fcdc3800af309363f6250104c8"},{"url":"https://git.kernel.org/stable/c/22441be29ec27c693f40c1ef499093275ef529d1"},{"url":"https://git.kernel.org/stable/c/79fd0b0161506fc9507bf7a6fe4c975a857a5be8"},{"url":"https://git.kernel.org/stable/c/f78cf36cabf911da348ea80e4e9f430d74f6905c"},{"url":"https://git.kernel.org/stable/c/81aa608ac3a56cdd4aab0bd12442ed529a24ba31"},{"url":"https://git.kernel.org/stable/c/9df2fbe563194da1967a5db083442186c1323efe"}],"title":"media: cedrus: fix memory leak in cedrus_init_ctrls()","x_generator":{"engine":"bippy-1.2.0"}}}}