From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D584B49DB8B for ; Thu, 24 Sep 2026 15:21:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790263294; cv=none; b=pMjI7XxnzD/A2rjxV1TZpXkUqcZ1T47kwQnbomb0hXcoRiAtvICyu7H3+O9oDlrL2L8b48HzkDWZuBIoUFTPV6UMSwpwHvU+9X6jmvWWTBcl2BwMcWZ1X5q2G2g+KFJeBtHwnnu/JnsIk0QLz5O2HeQTxxi29NZdVcMyqOhIXFc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790263294; c=relaxed/simple; bh=ycFcMzs6gSShqrgSmJlChhmWgQTcBT8aIxfuKaCgzWk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=svjf+u8G6YVubrvOfPJUQ/XllIO8z7cKusJmKlR5iFaM0wIGVt83SbAKkLVtGERpLesYJdOoQYyPPVz5gMt3VcQWWyA5+Exqaqv1etd6lhzPAGvDKdA29SyxrlK59NRRFijfdvMkGZ22kxYnjf4Btx6i44d7qw/UxHk/nCZ/cWs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=sHrDcxW9; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="sHrDcxW9" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D3B6B1F000FF; Thu, 24 Sep 2026 15:21:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790263292; bh=LdjKpTQiuiZq47JgucfDuCR2wuKgIoBp5DuAt/QYCwc=; h=From:To:Cc:Subject:Date:Reply-To; b=sHrDcxW9D4qGX2wlrPkrRVvaOX6zQoCMxgM5pjsh3P/GRHnxU8ySE0TKl6RvK+Gdq 9XTHGnMRFL/flenZAgcs657kSEgMu2k7DXsD7o9L0wbRUUSeHjCpjAtX4rCVXQ9XGE EN8r9pJM7sMr2KBgKJcSBadBPtzrH0b9ySwDlIe0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-93223: staging: media: tegra-video: fix of_node_put() on VIP parse errors Date: Thu, 24 Sep 2026 17:21:07 +0200 Message-ID: <2026092407-CVE-2026-93223-7929@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3018; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=9MjIoEizWKWSoEGLf+94nJ2pq4qF3ETBPnE5rbULQWA=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlb7R9bMv/vzdjySC6PxfZYvuaheK32CT8ErNjDfWMPh 2tPWx7ZEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABORqWaYpxSwx6k1TuJ3i0no lo70K0tlSh+WMiyYs1X/pfofu1tLjT8d1uS4yiegc/YwAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: staging: media: tegra-video: fix of_node_put() on VIP parse errors tegra_vip_channel_of_parse() initializes np from dev->of_node without taking a reference, but its error paths drop one through the err_node_put label. This underflows the refcount of the VIP device's OF node when endpoint parsing fails on a malformed device tree. The only reference the function takes on np is the success-path of_node_get() stored in vip->chan.of_node, and that one is already released by the tegra_vip_init() error path and by tegra_vip_exit(). Return errors directly instead of jumping to the bogus cleanup label. The Linux kernel CVE team has assigned CVE-2026-93223 to this issue. Affected and fixed versions =========================== Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.6.157 with commit a3783800c9475fa58b8db0885893f96a23f949da Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.12.109 with commit 1295ba29ac590bbb5c4a586afd408018168af10b Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 6.18.50 with commit 656d047dc0c29c0964d840217a0593f16aa9bc5e Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 7.2.4 with commit fc9937019cf7e2fe4e29f9341e6400bcd2cde721 Issue introduced in 6.5 with commit e740d199cf0ff1e53ddc2ab067c0a09b55845d68 and fixed in 7.3-rc1 with commit 7393372f79db940acff206b43e2905685a0c57ad Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-93223 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/staging/media/tegra-video/vip.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a3783800c9475fa58b8db0885893f96a23f949da https://git.kernel.org/stable/c/1295ba29ac590bbb5c4a586afd408018168af10b https://git.kernel.org/stable/c/656d047dc0c29c0964d840217a0593f16aa9bc5e https://git.kernel.org/stable/c/fc9937019cf7e2fe4e29f9341e6400bcd2cde721 https://git.kernel.org/stable/c/7393372f79db940acff206b43e2905685a0c57ad