CVE-2026-89741: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-dev: fix error handling in __video_register_device()" This reverts commit 2a934fdb01db6458288fc9386d3d8ceba6dd551a. The intentions of that patch were good, but it doesn't work. The idea is that if device_register fails, you have to do a put_device to let the ref counter release resources. However, the V4L2 API says that if video_register_device() fails, then you have to call video_device_release(), which kfree()s the video_device struct. But the put_device() will already have freed the struct, so you end up in a double-free scenario. There is not really a good way of fixing this without breaking video_register_device() into two parts, one that initializes everything, and one that does the actual device_register, and then converting all V4L2 drivers to this new model. That is a massive job, and it is very unlikely that device_register will fail. So rather than ending up in a double-free scenario, just revert this patch, and in that case we'll have a small memory leak. Which is a lot more robust.

Affected products

  • Linux Linux: from 5.10.239, before 5.10.270 (fixed in 5.10.270); from 5.15.186, before 5.15.221 (fixed in 5.15.221); from 6.1.142, before 6.1.188 (fixed in 6.1.188); from 6.6.95, before 6.6.157 (fixed in 6.6.157); from 6.12.35, before 6.12.109 (fixed in 6.12.109); from 5.4.295, before 5.5 (fixed in 5.5); …

Published 2026-09-11. Last modified 2026-09-14.