Executive brief
A vulnerability was identified in the Linux kernel's driver for the Techwell TW9906 video decoder. A flaw in how the system handles initialization errors can lead to a memory leak, where system memory is not properly released. Over time, repeated triggers of this error could exhaust available system memory, potentially leading to a system crash or performance degradation.
Technical details
A memory leak exists in the tw9906_probe() function within drivers/media/i2c/tw9906.c of the Linux kernel. The vulnerability occurs because the error handling path for write_regs() fails to call v4l2_ctrl_handler_free(), leaving memory allocated by v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() unreferenced but not freed. A local attacker with the ability to trigger probe failures for this specific i2c device could repeatedly leak memory, eventually leading to a denial of service (DoS) through resource exhaustion. The issue has been resolved by ensuring v4l2_ctrl_handler_free() is called during the affected error path.
Affected products
- Linux Linux Kernel 3.10 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-03-04: patched
References
- https://git.kernel.org/stable/c/0c33338514d8246280533a77091e6b6ee548c606
- https://git.kernel.org/stable/c/377a7756914364d72550fc86ca0f404ef1d96141
- https://git.kernel.org/stable/c/59420d5d9c46b084e21f9ea6ce79fc79ae9e414c
- https://git.kernel.org/stable/c/9548a8bbf511a252a9848f96220c6b95c9a3b918
- https://git.kernel.org/stable/c/cad237b6c875fbee5d353a2b289e98d240d17ec8
- https://git.kernel.org/stable/c/ccb92def042a3636ed47f25a30bd553788e5191e
- https://git.kernel.org/stable/c/e9a490937942f18205dac7b6b192975ef1369ae1