Junglewise Threat Intelligence

CVE-2026-93070: Linux kernel ipu6 double-free in auxiliary device cleanup

CVE-2026-93070 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Intel IPU6 media driver contains a double-free vulnerability in device initialization error paths. When the image processing unit fails to initialize, memory is freed twice, potentially causing a system crash or denial of service. This affects systems using the ipu6 hardware driver for camera or video processing.

Technical details

The vulnerability is a double-free (use-after-free) in the ipu6 driver's error handling paths. The root cause: when ipu6_bus_initialize_device() initializes an auxiliary device (isys or psys), the device release callback ipu6_bus_release() assumes ownership of freeing the pdata structure. However, error paths in ipu6_isys_init() and ipu6_psys_init() manually call kfree(pdata) after calling put_device(), which triggers the release callback. This causes the same memory to be freed twice. The vulnerability is reachable if MMU initialization fails or auxiliary_device_add() fails, both occurring after the initial bus_initialize_device() call. A fix involves removing the manual kfree(pdata) calls and relying solely on the device release callback to manage memory.

Affected products

  • Linux Linux kernel 5.x and 6.x (specific versions affected in ipu6 driver subsystem)

Timeline

  • 2026-09-17: disclosed: CVE-2026-93070 published
  • 2026-07-08: patched: Fix committed by Ruoyu Wang (upstream commit 9be07216af4cfc4813e1a46ce26407d31ea845de)
  • 2026-09-14: other: Fix merged to stable kernel trees by Greg Kroah-Hartman

References

Related threats