Executive brief
A vulnerability was identified in the Linux kernel's Renesas Input Video Control (IVC) driver, which manages video data processing. Due to a synchronization error, the system could attempt to modify video data buffers simultaneously from different processes, potentially leading to system instability or crashes. This issue has been resolved in recent kernel updates.
Technical details
A race condition exists in the Renesas RZV2H IVC driver (drivers/media/platform/renesas/rzv2h-ivc/rzv2h-ivc-video.c) due to improper locking. In the rzv2h_ivc_transfer_buffer() function, which executes within a workqueue, the list_del() operation on the buffer queue was performed outside of the spinlock-protected critical section. This allows for concurrent modification of the rzv2h_ivc::buffers.queue by other threads or interrupts. An attacker with local access could potentially exploit this race condition to cause a kernel oops or memory corruption. The fix moves the list deletion and current buffer assignment inside the spinlock-protected scope.
Affected products
- Linux Linux Kernel 6.19, 7.0.9, 7.1
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory