CVE-2026-68216

Source
https://cve.org/CVERecord?id=CVE-2026-68216
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68216.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68216
Downstream
Published
2026-08-10T12:00:35Z
Modified
2026-08-21T03:30:21Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: pwc: Return queued buffers on start_streaming() failure
Details

In the Linux kernel, the following vulnerability has been resolved:

media: pwc: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.

pwc's start_streaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutex_lock_interruptible() was interrupted by a signal. Call the existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED before returning (matching the state already used by the pwc_isoc_init() error path in the same function).

This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68216.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478
Fixed
d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3
Fixed
0362ae30b61b3053ee3095c1b8f179197ec4f539
Fixed
fa78e590852751d3ad32f33f6b4e210fe6ccbe9b
Fixed
f2f9fcacd81953dde6cb86312ab13ca13e689664
Fixed
5d7cc2634c3843a1414a0f6407aa17f1f91dee60
Fixed
cb16b79a2be2cec9c3ebe4147490817c4d8b1de3
Fixed
a4f8f629983f643333e49df90557805469bcbb25
Fixed
975b2ee20e569d47821e4f6c9761b4664d48a6a4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68216.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.5.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68216.json"