CVE-2026-68223
Last modified
CVE-2026-68223 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open() function previously jumped directly to err_m2m_release when vdec_init_ctrls() failed, skipping release of the m2m context. This caused a resource leak. Fix it by introducing a proper err_m2m_ctx_release label that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before releasing the m2m device. This was identified via kmemleak: unreferenced object 0xffff0000205d6878 (size 8): comm "v4l_id", pid 5289, jiffies 4294938580 hex dump (first 8 bytes): 40 d2 49 18 00 00 ff ff @.I..... backtrace (crc d3204599): kmemleak_alloc+0xc8/0xf0 __kvmalloc_node_noprof+0x60c/0x850 v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev] vdec_open+0x1f4/0x788 [meson_vdec] v4l2_open+0x144/0x460 [videodev] chrdev_open+0x1ac/0x500 do_dentry_open+0x3f0/0xfe8 vfs_open+0x68/0x320 do_open+0x2d8/0x9a8 path_openat+0x1d0/0x4f0 do_filp_open+0x190/0x380 do_sys_openat2+0xf8/0x1b0 __arm64_sys_openat+0x13c/0x1e8 invoke_syscall+0xdc/0x268 el0_svc_common.constprop.0+0x178/0x258 do_el0_svc+0x4c/0x70.
Description
In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open() function previously jumped directly to err_m2m_release when vdec_init_ctrls() failed, skipping release of the m2m context. This caused a resource leak. Fix it by introducing a proper err_m2m_ctx_release label that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before releasing the m2m device. This was identified via kmemleak: unreferenced object 0xffff0000205d6878 (size 8): comm "v4l_id", pid 5289, jiffies 4294938580 hex dump (first 8 bytes): 40 d2 49 18 00 00 ff ff @.I..... backtrace (crc d3204599): kmemleak_alloc+0xc8/0xf0 __kvmalloc_node_noprof+0x60c/0x850 v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev] vdec_open+0x1f4/0x788 [meson_vdec] v4l2_open+0x144/0x460 [videodev] chrdev_open+0x1ac/0x500 do_dentry_open+0x3f0/0xfe8 vfs_open+0x68/0x320 do_open+0x2d8/0x9a8 path_openat+0x1d0/0x4f0 do_filp_open+0x190/0x380 do_sys_openat2+0xf8/0x1b0 __arm64_sys_openat+0x13c/0x1e8 invoke_syscall+0xdc/0x268 el0_svc_common.constprop.0+0x178/0x258 do_el0_svc+0x4c/0x70
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 3e7f51bd96077acad6acd7b45668f65b44233c4e, < c6cd08a71a630f19b10c318e76e3c56e1dd10e00; >= 3e7f51bd96077acad6acd7b45668f65b44233c4e, < 2cf0171ad594860e31723c671e37824ce12c01ea; >= 3e7f51bd96077acad6acd7b45668f65b44233c4e, < 1391b75bf0119b5d37f1c1c3078d452a01967f9b; >= 3e7f51bd96077acad6acd7b45668f65b44233c4e, < 99f3527bd1a27ff798d59177ed045b0dd87deaef; >= 3e7f51bd96077acad6acd7b45668f65b44233c4e, < 940f161f734b25f175a95d2684c2021f6323693a |
| Linux | Linux | 5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68223?
How severe is CVE-2026-68223?
How do I fix CVE-2026-68223?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68217In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68218In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68219In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68220In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68221In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68222In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68224In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68225In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68226In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68227In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68228In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68229In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
