SB20260812328 - Race condition in Linux kernel test-drivers vivid driver



SB20260812328 - Race condition in Linux kernel test-drivers vivid driver

Published: August 12, 2026

Security Bulletin ID SB20260812328
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Race condition (CVE-ID: CVE-2026-68204)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause unexpected results.

The vulnerability exists due to improper state management in vivid_update_format_cap() and vivid_update_format_out() when changing CROP, COMPOSE, or SCALE capability controls after REQBUFS and before STREAMON while the queue state is not properly enforced. A local user can change these controls to cause unexpected results.

The issue affects the vivid media test driver during the window between buffer request setup and the start of streaming.


Remediation

Install update from vendor's website.