Use-after-free in Linux kernel - CVE-2026-64421
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in mxc_isi_remove() and the imx8-isi media cleanup path when removing the imx8_isi module. A local user can trigger module removal to cause a denial of service.
The issue occurs because media links are removed after the media entity pads they reference have already been freed.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64421
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/b670bf89824ede5d07d20bb9bfbafb754846081d
- https://git.kernel.org/stable/c/ba2aa5d325270cd965c44458c5ff5ab555e6af51
- https://git.kernel.org/stable/c/c12a5b2261351cd3b03921ce4720332ff5184b50
- https://git.kernel.org/stable/c/d22fb719654bfde6f682c9f14629f5f9534175b7
- https://git.kernel.org/stable/c/ef382a6baf0a95cf199fdf6bba2fd08e58b0a249