CVE-2026-68225

Source
https://cve.org/CVERecord?id=CVE-2026-68225
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68225.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68225
Downstream
Published
2026-08-10T12:00:47Z
Modified
2026-08-18T03:31:02Z
Summary
media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
Details

In the Linux kernel, the following vulnerability has been resolved:

media: i2c: alvium: fix critical pointer access in alvium_ctrl_init

The current implementation of alvium_ctrl_init creates several controls in function alvium_ctrl_init and uses the returned pointer without check. That can cause write access over NULL-pointer for several controls. The reworked code checks the pointers before adding flags.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68225.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0a7af872915ee34668edf7e4018648a226d9e7f9
Fixed
4bacfda44d36f165f6cb57bea408912886400ffa
Fixed
7337c88205ed0ffc654f40266be0d3c3eb15fb29
Fixed
eb2f934646aefb06314cecd1deb020794829b207
Fixed
4f6f28ff24709710c08557c127b3e4c3fb1b4159

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68225.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68225.json"