Junglewise Threat Intelligence

CVE-2026-89741: Linux kernel V4L2 double-free in device registration error handling

CVE-2026-89741 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's video device registration function (v4l2-dev) contained a double-free memory error when device registration fails. An attacker or faulty driver could trigger this condition, potentially causing a kernel crash or enabling privilege escalation. This affects all systems using V4L2 video device drivers (cameras, video capture devices, etc.).

Technical details

The vulnerability is a double-free error in the __video_register_device() function in drivers/media/v4l2-core/v4l2-dev.c. When device_register() fails, the patched code called put_device() to release the device reference, but the V4L2 API contract requires callers to invoke video_device_release() on failure, which also frees the video_device structure. This results in a use-after-free/double-free scenario. The root cause is an API mismatch between the device registration layer and V4L2's documented error handling contract. A fix would require substantial refactoring of all V4L2 drivers. The revert trades a potential double-free (exploitable but unlikely given device_register() rarely fails) for a small memory leak under this failure condition.

Affected products

  • Linux Linux kernel all versions with the vulnerable error handling code (reverted in subsequent patches)

Timeline

  • 2026-09-11: disclosed

References

Related threats