Executive brief
A vulnerability was identified in the Linux kernel's MediaTek JPEG driver that could lead to a system crash or unauthorized memory access. The issue occurs when the system attempts to close a JPEG processing task while background work is still running, causing the software to access memory that has already been deleted. This could potentially be exploited by a local user to cause a denial-of-service (system crash) or potentially gain elevated privileges.
Technical details
A use-after-free (UAF) vulnerability exists in the mtk-jpeg driver within the Linux kernel's media subsystem. The root cause is located in the mtk_jpeg_release() function, which frees the context structure (ctx) without ensuring that pending or running work queued in ctx->jpeg_work has been cancelled. This creates a race condition where the workqueue callback (mtk_jpegenc_worker) may attempt to access the context memory after it has been deallocated by kfree(). An attacker with local access could trigger this race by closing the device file descriptor while a JPEG encoding or decoding operation is active. The fix involves calling cancel_work_sync() before acquiring the device mutex to ensure all background tasks are completed or terminated before the memory is freed.
Affected products
- Linux Linux Kernel Fixed in 6.9 and various stable branches
Timeline
- 2026-03-04: other: Patch authored
- 2026-05-27: disclosed: CVE published
- 2026-05-27: advisory: NVD advisory published
References
- https://git.kernel.org/stable/c/0498b27a1542021d90269d58347501d4c3ccd84e
- https://git.kernel.org/stable/c/2209fdae5c2f615930c9af1379c1cfca199ec5d8
- https://git.kernel.org/stable/c/26506a30e0e26d612f82a7bf0e395626968a44e6
- https://git.kernel.org/stable/c/34c519feef3e4fcff1078dc8bdb25fbbbd10303f
- https://git.kernel.org/stable/c/e78c39f720679fcf3a2eacd82725ec3ea2648301