Executive brief
A memory leak vulnerability was identified in the Linux kernel's Wave5 video processing unit (VPU) driver. This driver is responsible for hardware-accelerated video encoding and decoding on certain platforms. If the system runs out of memory while trying to open a video stream, the driver fails to clean up previously allocated resources, which could eventually lead to system instability or a crash if triggered repeatedly.
Technical details
A memory leak exists in the wave5_vpu_open_enc() and wave5_vpu_open_dec() functions within the Chips&Media Wave5 VPU driver. The vulnerability occurs when kzalloc() successfully allocates a VPU instance, but a subsequent allocation for 'inst->codec_info' fails. In this error path, the function returns -ENOMEM without calling kfree() on the initial instance allocation. An attacker with the ability to repeatedly trigger these open calls under memory pressure could exhaust system memory. The issue has been resolved by adding the missing kfree() calls in the error handling paths.
Affected products
- Linux Linux Kernel wave5 driver
Timeline
- 2025-11-11: other: Patch authored
- 2026-05-27: advisory: CVE published