CVE-2026-72484: staging: most: video: avoid double free on video register failure
In the Linux kernel, the following vulnerability has been resolved:
staging: most: video: avoid double free on video register failure
compregistervideodev() allocates a videodevice with videodevicealloc() and releases it if videoregisterdevice() fails.
This can double free the videodevice when videoregisterdevice() reaches deviceregister() and that call fails:
videoregisterdevice() -> videoregisterdevice() -> deviceregister() fails -> putdevice(&vdev->dev) -> v4l2devicerelease() -> vdev->release(vdev) -> videodevicerelease(vdev)
compregistervideodev() -> videodevicerelease(mdev->vdev)
Use videodevicereleaseempty() while registering the device so that registration failure paths do not free mdev->vdev through vdev->release(). compregistervideodev() then releases mdev->vdev exactly once on failure. Restore videodevicerelease() after successful registration so the registered device keeps its normal lifetime handling.
This issue was found by a static analysis tool I am developing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72484?
CVE-2026-72484 has a risk rating of 23, indicating a significant security concern.
How do I fix CVE-2026-72484?
To mitigate CVE-2026-72484, update the Linux kernel to the latest version where this vulnerability has been resolved.
What type of vulnerability is CVE-2026-72484?
CVE-2026-72484 is classified as a double free vulnerability within the Linux kernel.
What systems are affected by CVE-2026-72484?
CVE-2026-72484 affects systems that use the affected versions of the Linux kernel with the staging: most: video driver.
What are the potential impacts of CVE-2026-72484?
The potential impacts of CVE-2026-72484 include software crashes and possible exploitation leading to system compromise.