CVE-2026-68205
Last modified
CVE-2026-68205 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() The v4l2 helper v4l2_async_register_subdev_sensor() calls v4l2_async_register_subdev(), which is a macro that expands to __v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module rather than the sensor driver module that originally set sd->owner.
Description
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() The v4l2 helper v4l2_async_register_subdev_sensor() calls v4l2_async_register_subdev(), which is a macro that expands to __v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module rather than the sensor driver module that originally set sd->owner. When v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then overwrites the sensor driver's owner with NULL. This causes the problem that the sensor module's reference count is never incremented during async registration, so the module can be removed while the subdevice is still in use by a notifier (e.g., a CSI-2 receiver bridge driver). Fix this by renaming v4l2_async_register_subdev_sensor() to __v4l2_async_register_subdev_sensor() with an added explicit module argument and introducing a wrapper macro: #define v4l2_async_register_subdev_sensor(sd) \ __v4l2_async_register_subdev_sensor(sd, THIS_MODULE) This ensures the sensor driver module is properly referenced even when the sensor driver does not init the owner field before calling v4l2_async_register_subdev_sensor() and prevents premature module removal.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= aef69d54755d45edefbf347a51efd1673d7daed9, < 47ef04cd13d38010b580056a9d8840aaab944841; >= aef69d54755d45edefbf347a51efd1673d7daed9, < caea6bc68c925d63ca33d21b2255f47181943d61; >= aef69d54755d45edefbf347a51efd1673d7daed9, < cf9732fd6c4f2f803ccfc46d89489b6635590270; >= aef69d54755d45edefbf347a51efd1673d7daed9, < 067887ff93fddbb3a3fb84c900bc654ecfe5ba61; >= aef69d54755d45edefbf347a51efd1673d7daed9, < 06cb687a5132fcffe624c0070576ab852ac6b568 |
| Linux | Linux | 4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68205?
How severe is CVE-2026-68205?
How do I fix CVE-2026-68205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6820The VikBooking Hotel Booking Engine & PMS plugin for WordPre…7.2
- CVE-2026-68200In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68201In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68202In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68203In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68204In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68206In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68207In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68208In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68209In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6821GitLab has remediated an issue in GitLab EE affecting all ve…4.3
- CVE-2026-68210In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
