SB2026061028 - Improper Initialization in Linux kernel common videobuf2 driver
Published: June 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Initialization (CVE-ID: CVE-2026-46312)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization of vma flags in vb2_dma_sg_mmap() in the videobuf2 dma-sg memory-mapping path when mmap() is performed on an imported dma-buf. A local user can trigger the affected mmap operation to cause a denial of service.
The issue manifests as a kernel warning in drm_gem_mmap_obj() during mmap() of an imported dma-buf.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1a1360264f699521e001e7739009ee3ee3c6a4f5
- https://git.kernel.org/stable/c/21fade52ab9fb13368a5709e60b0d9909197aeae
- https://git.kernel.org/stable/c/7254b31a13aaa0c2c0f9ffbc335b718656117ff4
- https://git.kernel.org/stable/c/b4cf91658a636618f1437beec971dec25dec28eb
- https://git.kernel.org/stable/c/feb17524aa4ec337749344be0db52b88663e25ab