Executive brief
A race condition in the Linux kernel's Amphion video processing unit (VPU) driver can lead to a system crash (kernel panic). This occurs when the system attempts to process a video task at the same time the task's context is being released. An exploit would result in a denial-of-service, impacting system availability.
Technical details
A race condition exists in the Linux kernel's media/amphion driver between v4l2_m2m_ctx_release() and v4l2_m2m_try_run(). The vulnerability is a use-after-free (UAF) where the m2m_ctx is freed by the release function while the try_run function is attempting to execute device_run with that same context. This occurs because the Amphion VPU driver was incorrectly utilizing the m2m framework's job scheduling. The fix involves implementing a job_ready callback that always returns 0 and removing the job_abort callback to prevent the m2m framework from scheduling jobs that the driver handles internally. Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux Kernel amphion vpu driver
Timeline
- 2026-03-06: other: Patch authored
- 2026-05-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/42dc622776f3ce1a6c31b13bdc686f7295e3b323
- https://git.kernel.org/stable/c/6be2cb75bc1300080cfc8051579f22efae9401f7
- https://git.kernel.org/stable/c/8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e
- https://git.kernel.org/stable/c/da4f46c5cf1d26e6b09418ad453e152f2e75a02c
- https://git.kernel.org/stable/c/fdc150dac1adb9a98be9d6956cff0348838b024a