Executive brief
The Linux kernel's video device registration function (v4l2-dev) contained a double-free memory error when device registration fails. An attacker or faulty driver could trigger this condition, potentially causing a kernel crash or enabling privilege escalation. This affects all systems using V4L2 video device drivers (cameras, video capture devices, etc.).
Technical details
The vulnerability is a double-free error in the __video_register_device() function in drivers/media/v4l2-core/v4l2-dev.c. When device_register() fails, the patched code called put_device() to release the device reference, but the V4L2 API contract requires callers to invoke video_device_release() on failure, which also frees the video_device structure. This results in a use-after-free/double-free scenario. The root cause is an API mismatch between the device registration layer and V4L2's documented error handling contract. A fix would require substantial refactoring of all V4L2 drivers. The revert trades a potential double-free (exploitable but unlikely given device_register() rarely fails) for a small memory leak under this failure condition.
Affected products
- Linux Linux kernel all versions with the vulnerable error handling code (reverted in subsequent patches)
Timeline
- 2026-09-11: disclosed