CVE-2026-68228

Unknown

Last modified

CVE-2026-68228 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to finish_encode During encoder processing, there is a case where the IRQ response could return the buffer back to userspace via v4l2_m2m_buf_done call. In this time, userspace could queue up this same buffer before start_encode removes the index from the ready queue.

Description

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to finish_encode During encoder processing, there is a case where the IRQ response could return the buffer back to userspace via v4l2_m2m_buf_done call. In this time, userspace could queue up this same buffer before start_encode removes the index from the ready queue. This would then lead to a case where the buffer in the ready queue could be a self loop due to the WRITE_ONCE(prev->next, new) call in __list_add. When __list_del is finally called, the loop is already made so nothing points back to ready queue list head and pointers are poisoned. A buffer should not be marked as DONE before the buffer is removed from m2m ready queue. Move removal entirely to finish_encode.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 9707a6254a8a6b978bde811a44fe07d86c229d1c, < 1ee2b2b189ddc7b23c8eee1145de42b8bd19fb06; >= 9707a6254a8a6b978bde811a44fe07d86c229d1c, < f24ca8b53fe15db40957bdaa40c9aa68e1557bbe; >= 9707a6254a8a6b978bde811a44fe07d86c229d1c, < d681227ce43bfd74b6eb69beecd9b0bec1fd8b48; >= 9707a6254a8a6b978bde811a44fe07d86c229d1c, < b20157147089a9c16a38c7810e2fe6f2df8e3277
LinuxLinux6.8

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68228?
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to finish_encode During encoder processing, there is a case where the IRQ response could return the buffer back to userspace via v4l2_m2m_buf_done call. In this time, userspace could queue up this same buffer before start_encode removes the index from the ready queue. This would then lead to a case where the buffer in the ready queue could be a self loop due to the WRITE_ONCE(prev->next, new) call in __list_add. When __list_del is finally called, the loop is already made so nothing points back to ready queue list head and pointers are poisoned. A buffer should not be marked as DONE before the buffer is removed from m2m ready queue. Move removal entirely to finish_encode.
How severe is CVE-2026-68228?
Severity scoring for CVE-2026-68228 is pending analysis.
How do I fix CVE-2026-68228?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68228?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST