Executive brief
A vulnerability was identified in the Linux kernel's TW9903 video decoder driver, which is used to support specific video hardware. A flaw in how the driver handles initialization errors can lead to a memory leak. If exploited, this could allow a local user to gradually consume system memory, potentially leading to a system crash or reduced performance.
Technical details
A memory leak exists in the tw9903_probe() function within drivers/media/i2c/tw9903.c of the Linux kernel. The vulnerability occurs because the driver fails to call v4l2_ctrl_handler_free() when an error is encountered during the write_regs() phase of device initialization. This leaves memory allocated by v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() unreferenced but not freed. A local attacker with the ability to trigger device probing or repeated initialization failures could exhaust kernel memory, leading to a denial of service (DoS). The issue has been resolved by adding the missing free call to the error path.
Affected products
- Linux Linux Kernel 3.10 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2025-12-23: disclosed: Initial patch authored
- 2026-05-06: advisory: CVE published by kernel.org
References
- https://git.kernel.org/stable/c/32f0493506313775d3bd448de34762b6538da6bd
- https://git.kernel.org/stable/c/92537a15780b6d0281fd8286f93fbc3652e35f48
- https://git.kernel.org/stable/c/9cb9eca33d20316ed3c7a938793b8735ac3e128b
- https://git.kernel.org/stable/c/9cea16fea47e5553f51d10957677ff735b1eff03
- https://git.kernel.org/stable/c/a114918270f0d95c607d69b03a244e6afe54813f
- https://git.kernel.org/stable/c/add02a3fb1fd71b004f0ed824cbac00f850de558
- https://git.kernel.org/stable/c/cc7aeed33e4f55c76f35f0fca73e4dfe12a63a3a