SB2026091767 - Memory leak in Linux kernel sunxi cedrus driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-89896)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in the V4L2 control handler in cedrus_init_ctrls() when allocation of ctx->ctrls fails. A local user can trigger the allocation failure path to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/22441be29ec27c693f40c1ef499093275ef529d1
- https://git.kernel.org/stable/c/6fabacc3b79a528450aef4c32464da2ec681049e
- https://git.kernel.org/stable/c/729a1ffab968b3c493f61d1cd683f5bafec500ea
- https://git.kernel.org/stable/c/79fd0b0161506fc9507bf7a6fe4c975a857a5be8
- https://git.kernel.org/stable/c/81aa608ac3a56cdd4aab0bd12442ed529a24ba31
- https://git.kernel.org/stable/c/9df2fbe563194da1967a5db083442186c1323efe
- https://git.kernel.org/stable/c/ce5693b6e3a693fcdc3800af309363f6250104c8
- https://git.kernel.org/stable/c/f78cf36cabf911da348ea80e4e9f430d74f6905c