CVE-2026-68208: media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()
In the Linux kernel, the following vulnerability has been resolved:
media: ti: vpe: Fix the error code of devmkzalloc() in vipprobeslice()
In vipprobeslice(), the error check for devmkzalloc() incorrectly uses PTRERRORZERO() which returns 0 for NULL pointer.
Return -ENOMEM for devmkzalloc() failure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In vip_probe_slice(), change the error check for devm_kzalloc() to return -ENOMEM on failure; do not use PTR_ERR_OR_ZERO() because it returns 0 for NULL pointer.
Linux kernel (media: ti: vpe) vip_probe_slice() error handling for devm_kzalloc() = Return -ENOMEM when devm_kzalloc() fails (instead of using PTR_ERR_OR_ZERO() that returns 0 for NULL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68208?
The severity of CVE-2026-68208 is rated as 4.
What does CVE-2026-68208 affect?
CVE-2026-68208 affects the Linux kernel, specifically the media subsystem related to Texas Instruments video processing engines.
How do I fix CVE-2026-68208?
To fix CVE-2026-68208, ensure that your Linux kernel version has been updated to include the patch that corrects the error handling in vip_probe_slice().
What is the impact of CVE-2026-68208?
The impact of CVE-2026-68208 may lead to memory allocation issues in the video processing engine if the error code is not handled correctly.
When was CVE-2026-68208 published?
CVE-2026-68208 was published on August 10, 2026.