Executive brief
A vulnerability was identified in the Linux kernel's cx23885 driver, which manages certain video and audio capture hardware. A flaw in how the driver handles errors during hardware setup can lead to a resource leak. This could allow a local user to cause a system crash or instability, resulting in a denial of service.
Technical details
A resource leak exists in the cx23885 driver within the Linux kernel's media subsystem. Specifically, the snd_cx23885_hw_params() function in drivers/media/pci/cx23885/cx23885-alsa.c fails to call cx23885_alsa_dma_unmap() when an error occurs during the execution of cx23885_risc_databuffer(). This missing unmap operation in the error path results in a failure to release DMA resources acquired by cx23885_alsa_dma_map(). A local attacker with sufficient privileges to interact with the media device could exploit this to exhaust system resources, leading to a kernel panic or denial of service. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.18 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/0b7f56084cc3d7766bf274b71cd14cc9674b76bf
- https://git.kernel.org/stable/c/141c81849fab2ad4d6e3fdaff7cbaa873e8b5eb2
- https://git.kernel.org/stable/c/505630dd1ebf4b53d3f2866c057ddd93157a24d8
- https://git.kernel.org/stable/c/544215cc37d032ccaf1919852c05e2439a4d7540
- https://git.kernel.org/stable/c/9544b73cad4ee667fed6a60f71570c58a870a735
- https://git.kernel.org/stable/c/9c0a6ff538660c36a98081916a24f08d55a91331
- https://git.kernel.org/stable/c/fc4df593a8ffded2f77d69a73ecb51d364932ca5