SB20260812322 - Use-after-free in Linux kernel media dvb-frontends driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68214)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in rtl2832_remove() when removing a device while concurrent I2C transfers are still in flight through the mux adapter. A local user can trigger device removal during concurrent I2C activity to cause a denial of service.
The issue arises because delayed work may be rescheduled after cancellation by a concurrent thread during device teardown.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309
- https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042
- https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c
- https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750
- https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16