CVE-2026-31583

EUVD-2026-25476
In the Linux kernel, the following vulnerability has been resolved:

media: em28xx: fix use-after-free in em28xx_v4l2_open()

em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock,
creating a race with em28xx_v4l2_init()'s error path and
em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct
and set dev->v4l2 to NULL under dev->lock.

This race leads to two issues:
 - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler,
   since the video_device is embedded in the freed em28xx_v4l2 struct.
 - NULL pointer dereference in em28xx_resolution_set() when accessing
   v4l2->norm, since dev->v4l2 has been set to NULL.

Fix this by moving the mutex_lock() before the dev->v4l2 read and
adding a NULL check for dev->v4l2 under the lock.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 6.6.136
linuxlinux_kernel
6.12 ≤
𝑥
< 6.12.83
linuxlinux_kernel
6.13 ≤
𝑥
< 6.18.24
linuxlinux_kernel
6.19 ≤
𝑥
< 6.19.14
linuxlinux_kernel
7.0 ≤
𝑥
< 7.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.176-1
fixed
bookworm (security)
6.1.177-1
fixed
bullseye
vulnerable
bullseye (security)
5.10.259-1
fixed
forky
7.1.3-1
fixed
sid
7.1.4-1
fixed
trixie
6.12.94-1
fixed
trixie (security)
6.12.96-1
fixed
linux-6.1
bullseye (security)
6.1.176-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-64kb
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default-base
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
kernel-obs-build
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-source
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kernel
Azure Linux 3.0
0:6.6.137.1-1.azl3
fixed