Junglewise Threat Intelligence

CVE-2026-80650: Linux kernel gc2235 camera driver use-after-free and memory leak

CVE-2026-80650 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The gc2235 camera driver in the Linux kernel has incorrect error handling in its initialization routine. If initialization fails at certain points, the driver either attempts to use freed memory or leaks allocated resources. This could lead to system instability or allow an attacker with kernel access to trigger memory corruption.

Technical details

The vulnerability exists in gc2235_probe() error paths. If media_entity_pads_init() fails, gc2235_remove() is called which frees the device structure, but execution continues to atomisp_register_i2c_module(), resulting in use-after-free (UAF). Additionally, if atomisp_register_i2c_module() fails, the media entity and control handler remain initialized while the device is leaked. The root cause is improper error path handling where gc2235_remove() unconditionally cleans up resources not initialized at every failure point. The fix replaces gc2235_remove() calls with explicit unwinding labels that only free resources initialized up to the point of failure, in reverse order of initialization.

Affected products

  • Linux Linux kernel multiple stable versions through 6.19.y and later

Timeline

  • 2026-08-28: disclosed: CVE-2026-80650 published
  • 2026-04-02: patched: Fix authored by Yuho Choi
  • 2026-05-20: patched: Fix merged into mainline by Sakari Ailus
  • 2026-07-24: patched: Fix backported to stable trees

References

Related threats