SB2026091773 - Double free in Linux kernel media i2c driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-89887)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a kernel panic.
The vulnerability exists due to improper resource lifecycle management in the ov7740_remove() function when removing the ov7740 driver. A local user can trigger driver removal to cause a kernel panic.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/09453b467990e8ef8fe09f45a685f9a625248d33
- https://git.kernel.org/stable/c/25e2505866c577db2661e4d431f0907c6ec9a3b4
- https://git.kernel.org/stable/c/5d1b3dea5a44124bab6c14a2d71b977dabed54e7
- https://git.kernel.org/stable/c/7512838a19af0a284a58435292243fad21e57ff1
- https://git.kernel.org/stable/c/81e9765878d3ac8ad18e3a683332b5d6bc3a0e33
- https://git.kernel.org/stable/c/8a02ee6c1c4e88f3a0442bd60d3c77db9a30db5e
- https://git.kernel.org/stable/c/9e4693436c7dcf8584002500ce4b434b79bbf9ed
- https://git.kernel.org/stable/c/af81f35e4f429e769b784754e1aa4d7a922470ac