CVE-2026-68231

Source
https://cve.org/CVERecord?id=CVE-2026-68231
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68231.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68231
Downstream
Published
2026-08-10T12:00:54Z
Modified
2026-08-21T03:30:14Z
Summary
media: airspy: Return queued buffers on start_streaming() failure
Details

In the Linux kernel, the following vulnerability has been resolved:

media: airspy: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.

airspy_start_streaming() returned -ENODEV early when the USB device had been disconnected (s->udev == NULL) without returning any buffers that buf_queue() had already accepted. Take v4l2_lock first and jump to the existing err_clear_bit label, which already drains s->queued_bufs via vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.

This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68231.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
634fe5033951b80ef4b98d8f047cb1083d29170d
Fixed
badceeb82a9d8d8e98d07859f3c89130ae1998b9
Fixed
122ce0c0af629a8765ddf1adf6fb85c6db3d47cb
Fixed
bcdf261c4c29077fc3da6449f7eda77357046205
Fixed
877686a74ecdc93dcaee09dbac566e819059c9e7
Fixed
cd42623d698b59f1fe5768f78a4101c28d5feb2e
Fixed
73bd2779865372b1017d4f555b45270aa2d0d710
Fixed
170fcc945bc094b1c956bf555c070692826a3eff
Fixed
04344d0b4929caa94c0df72f767752aa0935ef5d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68231.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68231.json"