SB20260812328 - Race condition in Linux kernel test-drivers vivid driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-68204)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause unexpected results.
The vulnerability exists due to improper state management in vivid_update_format_cap() and vivid_update_format_out() when changing CROP, COMPOSE, or SCALE capability controls after REQBUFS and before STREAMON while the queue state is not properly enforced. A local user can change these controls to cause unexpected results.
The issue affects the vivid media test driver during the window between buffer request setup and the start of streaming.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/492c97cb50feaa60ccd7792d3d6b904ed8ec61bf
- https://git.kernel.org/stable/c/a9cd0e8fb0b21faaa71199d9d3feb305c18ff576
- https://git.kernel.org/stable/c/abaec6747304581f8d4a9936352fa10e13325f07
- https://git.kernel.org/stable/c/c2d1a2130c93f6d758af58590b86b2254c7a1dec
- https://git.kernel.org/stable/c/daf2d92669b4a659d805d88d811161c70cd325ee