SB20260812333 - Improper resource shutdown or release in Linux kernel sunxi sun4i-csi driver



SB20260812333 - Improper resource shutdown or release in Linux kernel sunxi sun4i-csi driver

Published: August 12, 2026

Security Bulletin ID SB20260812333
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper resource shutdown or release (CVE-ID: CVE-2026-68209)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the sun4i_csi_start_streaming() path of the sun4i-csi driver when handling streaming startup with an unsupported CSI format. A local user can trigger streaming initialization with a format that has no matching CSI format to cause a denial of service.

The issue occurs because queued video buffers are not returned on the error path after they have already been handed to the driver by the vb2 framework.


Remediation

Install update from vendor's website.