From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-93223: staging: media: tegra-video: fix of_node_put() on VIP parse errors
Date: Thu, 24 Sep 2026 17:21:07 +0200 [thread overview]
Message-ID: <2026092407-CVE-2026-93223-7929@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
staging: media: tegra-video: fix of_node_put() on VIP parse errors
tegra_vip_channel_of_parse() initializes np from dev->of_node without
taking a reference, but its error paths drop one through the
err_node_put label. This underflows the refcount of the VIP device's
OF node when endpoint parsing fails on a malformed device tree.
The only reference the function takes on np is the success-path
of_node_get() stored in vip->chan.of_node, and that one is already
released by the tegra_vip_init() error path and by tegra_vip_exit().
Return errors directly instead of jumping to the bogus cleanup label.
The Linux kernel CVE team has assigned CVE-2026-93223 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.6.157 with commit a3783800c9475fa58b8db0885893f96a23f949da
Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.12.109 with commit 1295ba29ac590bbb5c4a586afd408018168af10b
Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.18.50 with commit 656d047dc0c29c0964d840217a0593f16aa9bc5e
Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 7.2.4 with commit fc9937019cf7e2fe4e29f9341e6400bcd2cde721
Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 7.3-rc1 with commit 7393372f79db940acff206b43e2905685a0c57ad
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-93223
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/staging/media/tegra-video/vip.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/a3783800c9475fa58b8db0885893f96a23f949da
https://git.kernel.org/stable/c/1295ba29ac590bbb5c4a586afd408018168af10b
https://git.kernel.org/stable/c/656d047dc0c29c0964d840217a0593f16aa9bc5e
https://git.kernel.org/stable/c/fc9937019cf7e2fe4e29f9341e6400bcd2cde721
https://git.kernel.org/stable/c/7393372f79db940acff206b43e2905685a0c57ad
reply other threads:[~2026-09-24 15:21 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092407-CVE-2026-93223-7929@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.