CVE-2026-31585

EUVD-2026-25478
In the Linux kernel, the following vulnerability has been resolved:

media: vidtv: fix nfeeds state corruption on start_streaming failure

syzbot reported a memory leak in vidtv_psi_service_desc_init [1].

When vidtv_start_streaming() fails inside vidtv_start_feed(), the
nfeeds counter is left incremented even though no feed was actually
started. This corrupts the driver state: subsequent start_feed calls
see nfeeds > 1 and skip starting the mux, while stop_feed calls
eventually try to stop a non-existent stream.

This state corruption can also lead to memory leaks, since the mux
and channel resources may be partially allocated during a failed
start_streaming but never cleaned up, as the stop path finds
dvb->streaming == false and returns early.

Fix by decrementing nfeeds back when start_streaming fails, keeping
the counter in sync with the actual number of active feeds.

[1]
BUG: memory leak
unreferenced object 0xffff888145b50820 (size 32):
 comm "syz.0.17", pid 6068, jiffies 4294944486
 backtrace (crc 90a0c7d4):
  vidtv_psi_service_desc_init+0x74/0x1b0 drivers/media/test-drivers/vidtv/vidtv_psi.c:288
  vidtv_channel_s302m_init+0xb1/0x2a0 drivers/media/test-drivers/vidtv/vidtv_channel.c:83
  vidtv_channels_init+0x1b/0x40 drivers/media/test-drivers/vidtv/vidtv_channel.c:524
  vidtv_mux_init+0x516/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:518
  vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 [inline]
  vidtv_start_feed+0x33e/0x4d0 drivers/media/test-drivers/vidtv/vidtv_bridge.c:239
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.10 ≤
𝑥
< 6.6.136
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.83
linuxlinux_kernel
6.13 ≤
𝑥
< 6.18.24
linuxlinux_kernel
6.19 ≤
𝑥
< 6.19.14
linuxlinux_kernel
7.0 ≤
𝑥
< 7.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.176-1
fixed
bookworm (security)
6.1.177-1
fixed
bullseye
vulnerable
bullseye (security)
5.10.259-1
fixed
forky
7.1.3-1
fixed
sid
7.1.4-1
fixed
trixie
6.12.94-1
fixed
trixie (security)
6.12.96-1
fixed
linux-6.1
bullseye (security)
6.1.176-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-64kb
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default-base
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
kernel-obs-build
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-source
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kernel
Azure Linux 3.0
0:6.6.137.1-1.azl3
fixed