Race condition in Linux kernel - CVE-2026-68228
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the wave5 encoder buffer handling in drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c when processing encoder completion and re-queuing buffers. A local user can queue the same buffer before it is removed from the m2m ready queue to cause a denial of service.
The issue can result in a self-referential ready-queue entry, after which list pointers are poisoned when the entry is deleted.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-68228
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38