๐Ÿ” CVE Alert

CVE-2026-89880

UNKNOWN 0.0

media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(), rtl2832_sdr_alloc_urbs() and rtl2832_sdr_submit_urbs() in sequence and shares a single err: label that only unlocks the mutex and returns. When alloc_urbs() succeeds but submit_urbs() fails, or when alloc_urbs() itself returns -ENOMEM after alloc_stream_bufs() has already succeeded, the URBs and/or the coherent DMA stream buffers stay allocated while streaming reports failure to vb2. Two latent defects follow on the next VIDIOC_STREAMON: 1) rtl2832_sdr_alloc_stream_bufs() unconditionally resets dev->buf_num to 0 and overwrites dev->buf_list[]/dev->dma_addr[], permanently leaking the coherent DMA memory allocated by the previous attempt. 2) rtl2832_sdr_alloc_urbs() never resets dev->urbs_initialized and only increments it. After a second successful pass urbs_initialized can exceed MAX_BULK_BUFS, so the subsequent rtl2832_sdr_free_urbs() walks from urbs_initialized - 1 down to 0 and reads past the end of dev->urb_list[], passing garbage pointers to usb_free_urb(). Mirror the teardown that stop_streaming() already performs: on the error path call rtl2832_sdr_free_urbs() and rtl2832_sdr_free_stream_bufs() before unlocking. Both helpers are idempotent (free_urbs kills and zeros urbs_initialized; free_stream_bufs is gated on URB_BUF and clears the buf_num counter), so partial-failure paths and the no-allocation paths remain safe. Issue identified by automated review of the INV-003 series at https://sashiko.dev/

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
771138920eafa399f68d3492c8a75dfeea23474b < f14a713a36a5c87568430e9770896f2a8f5bbbb7 771138920eafa399f68d3492c8a75dfeea23474b < c819dea3a433ae790b829443fdcc1715d1586560 771138920eafa399f68d3492c8a75dfeea23474b < 0337ab0759285076a3f9dcfcc40906e69ab519b3 771138920eafa399f68d3492c8a75dfeea23474b < c91e8ae2b39c6da81f26f2c9877d3fd33a4465ce 771138920eafa399f68d3492c8a75dfeea23474b < 8bcf11a239eac4e224ad856277de9a36c91b1711 771138920eafa399f68d3492c8a75dfeea23474b < 26a2a985bbeee3eaa6f80ff7de732161a171ec9f 771138920eafa399f68d3492c8a75dfeea23474b < ac02b2c56ccef0788cea9b86990a8f349a3fc6d8 771138920eafa399f68d3492c8a75dfeea23474b < fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4
Linux / Linux
3.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f14a713a36a5c87568430e9770896f2a8f5bbbb7 git.kernel.org: https://git.kernel.org/stable/c/c819dea3a433ae790b829443fdcc1715d1586560 git.kernel.org: https://git.kernel.org/stable/c/0337ab0759285076a3f9dcfcc40906e69ab519b3 git.kernel.org: https://git.kernel.org/stable/c/c91e8ae2b39c6da81f26f2c9877d3fd33a4465ce git.kernel.org: https://git.kernel.org/stable/c/8bcf11a239eac4e224ad856277de9a36c91b1711 git.kernel.org: https://git.kernel.org/stable/c/26a2a985bbeee3eaa6f80ff7de732161a171ec9f git.kernel.org: https://git.kernel.org/stable/c/ac02b2c56ccef0788cea9b86990a8f349a3fc6d8 git.kernel.org: https://git.kernel.org/stable/c/fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4