Junglewise Threat Intelligence

CVE-2026-43146: Linux Kernel iris driver state inconsistency in iris_buffer.c

CVE-2026-43146 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's 'iris' media driver, which handles video processing on certain hardware. The issue occurs when the system fails to allocate memory for video buffers, potentially leaving the system in an unstable state. This could allow a local user to cause a system crash or denial of service, impacting operational availability.

Technical details

A vulnerability in the 'iris' media driver (drivers/media/platform/qcom/iris/) within the Linux kernel stems from improper list management during buffer creation. In the 'iris_create_internal_buffer' function, 'list_add_tail()' was previously called before 'dma_alloc_attrs()'. If the DMA allocation failed, the function returned -ENOMEM but left a partially initialized, invalid buffer pointer in the 'buffers->list'. This inconsistent state can lead to kernel instability or memory leaks. The fix reorders the operations to ensure buffers are only enqueued after successful allocation and adds a 'kfree()' call to clean up the buffer structure on failure. This is reachable by local users with access to the media subsystem.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2025-12-29: other: Patch authored
  • 2026-05-06: advisory: CVE published
  • 2026-05-06: disclosed: Vulnerability resolved in kernel tree

References

Related threats