PT-2026-44363 · Linux · Linux
Published
2026-05-28
·
Updated
2026-05-28
·
CVE-2026-46240
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
media: iris: Fix use-after-free in iris release internal buffers()
The recent change in commit 1dabf00ee206 ("media: iris: gen1: Destroy
internal buffers after FW releases") introduced a regression where
session release buf() may free the buffer. The caller,
iris release internal buffers(), continued to access
buffer after the
call, leading to a potential use-after-free.Fix this by setting BUF ATTR PENDING RELEASE before calling
session release buf(), and reverting the flag if the call fails. This
ensures no dereference occurs after potential freeing.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux