Memory leak in Linux kernel - CVE-2026-89896
Published: September 17, 2026
Vulnerability identifier: #VU150389
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89896
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in the V4L2 control handler in cedrus_init_ctrls() when allocation of ctx->ctrls fails. A local user can trigger the allocation failure path to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-89896
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/22441be29ec27c693f40c1ef499093275ef529d1
- https://git.kernel.org/stable/c/6fabacc3b79a528450aef4c32464da2ec681049e
- https://git.kernel.org/stable/c/729a1ffab968b3c493f61d1cd683f5bafec500ea
- https://git.kernel.org/stable/c/79fd0b0161506fc9507bf7a6fe4c975a857a5be8
- https://git.kernel.org/stable/c/81aa608ac3a56cdd4aab0bd12442ed529a24ba31
- https://git.kernel.org/stable/c/9df2fbe563194da1967a5db083442186c1323efe
- https://git.kernel.org/stable/c/ce5693b6e3a693fcdc3800af309363f6250104c8
- https://git.kernel.org/stable/c/f78cf36cabf911da348ea80e4e9f430d74f6905c