Executive brief
A vulnerability in the Linux kernel's em28xx driver, used for certain USB video capture devices, could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs due to a race condition when opening the device, which can lead to memory corruption. This could impact system stability and the confidentiality of data handled by the kernel.
Technical details
A race condition exists in the em28xx driver within the em28xx_v4l2_open() function. The function reads dev->v4l2 without holding the necessary dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(). This can result in a use-after-free when accessing vdev->ctrl_handler or a NULL pointer dereference in em28xx_resolution_set(). An attacker with local access could exploit this to cause a kernel panic or achieve arbitrary code execution in kernel mode. The fix involves moving the mutex acquisition before the pointer read and adding a NULL check.
Affected products
- Linux Linux Kernel up to 6.6.136, 6.12 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-06-01: patched
References
- https://git.kernel.org/stable/c/2cbf81f76842e46bdf25823c70e1db4044a65678
- https://git.kernel.org/stable/c/38a327221f7f765e7d853b7bafe47e342441ec85
- https://git.kernel.org/stable/c/3c0283a59e36e3707c4a81f4952e362d31f876b8
- https://git.kernel.org/stable/c/5fb2940327722b4684d2f964b54c1c90aa277324
- https://git.kernel.org/stable/c/6b9e66437cc6123ddedac141e1b8b6fcf57d2972
- https://git.kernel.org/stable/c/871b8ea8ef39a6c253594649f4339378fad3d0dd
- https://git.kernel.org/stable/c/a66485a934c7187ae8e36517d40615fa2e961cff