CVE Database
/

CVE-2026-31583

Back to search

CVE-2026-31583

Published: Apr 24, 2026

Modified: Jun 1, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct and set dev->v4l2 to NULL under dev->lock. This race leads to two issues: - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler, since the video_device is embedded in the freed em28xx_v4l2 struct. - NULL pointer dereference in em28xx_resolution_set() when accessing v4l2->norm, since dev->v4l2 has been set to NULL. Fix this by moving the mutex_lock() before the dev->v4l2 read and adding a NULL check for dev->v4l2 under the lock.

VendorProductVersions

Linux

Linux

affected
8139a4d583abad45eb987b5a99b3281b6d435b7e - < 3c0283a59e36e3707c4a81f4952e362d31f876b8
affected
8139a4d583abad45eb987b5a99b3281b6d435b7e - < 2cbf81f76842e46bdf25823c70e1db4044a65678
affected
8139a4d583abad45eb987b5a99b3281b6d435b7e - < 38a327221f7f765e7d853b7bafe47e342441ec85
affected
8139a4d583abad45eb987b5a99b3281b6d435b7e - < b5d141ea15f173f15b9f0a72965902f3428c0d92
affected
8139a4d583abad45eb987b5a99b3281b6d435b7e - < 5fb2940327722b4684d2f964b54c1c90aa277324

+4 more versions

Linux

Linux

affected
3.16
unaffected
0 - < 3.16
unaffected
5.10.258 - <= 5.10.*
unaffected
5.15.209 - <= 5.15.*
unaffected
6.1.175 - <= 6.1.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now