GHSA-33q9-xpr9-fmxvHighCVSS 8.4

In the Linux kernel, the following vulnerability has been resolved: media: saa7164: fix cleanup...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

media: saa7164: fix cleanup on resource allocation failure

saa7164_dev_setup() adds the device to the global saa7164_devlist before requesting the PCI BAR memory regions.

If get_resources() fails, saa7164_dev_setup() decrements the device count and returns an error, but leaves the device on saa7164_devlist. The probe error path then frees the device, leaving a dangling entry on the global list.

Reuse the existing MMIO mapping error path to remove the device from saa7164_devlist and decrement the device count before returning.

Also release BAR0 if it was successfully requested but the BAR2 request fails.

🔗 References (8)