Executive brief
A vulnerability was identified in the Linux kernel's Intel IPU7 media driver that could lead to system instability or crashes. The issue occurs during specific error handling sequences when initializing the camera imaging system, where the system might attempt to free the same memory twice or access memory that has already been released. This primarily impacts system availability and could potentially be used to cause a denial-of-service (system crash).
Technical details
This vulnerability exists in the staging media driver for Intel IPU7 (ipu7.c). The root cause is improper reference counting and memory management during error handling in ipu7_isys_init() and ipu7_psys_init(). Specifically, when ipu7_mmu_init() or ipu7_bus_add_device() fails, the code calls put_device(), which triggers the release function ipu7_bus_release() and frees the associated pdata. The driver then incorrectly calls kfree(pdata) again, resulting in a double-free. Furthermore, the driver attempted to dereference the device pointer (adev) to cast an error code after the device had already been released, leading to a use-after-free. The fix involves saving the error code before releasing the device and removing the redundant kfree calls.
Affected products
- Linux Linux Kernel 6.17 to 6.18.39, 7.1.4
Timeline
- 2026-04-13: other: Patch authored
- 2026-07-25: disclosed: CVE published