Answer in brief
CVE-2026-72484 records a Unknown severity vulnerability in staging: most: video: avoid double free on video register failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72484 records a Unknown severity vulnerability in staging: most: video: avoid double free on video register failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eab231c0398a91fbd294672bfe9e0ff45b368246 <009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <430ad4ea06a0767fb44a08e2212ceb3a996607ee || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <4928096212b78262dbbeab3b3abf2352278ce22d || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <80ed79787da3311f76b4d71d0ce7ab992a9e134d || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <43078449ad6236d839e4d707954d2e36b10a6706 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <7fc162453cfb7b8e93edb16287a84ba0130cac38 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <7cb1c5b32a2bfde961fff8d5204526b609bcb30a | 009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb, 430ad4ea06a0767fb44a08e2212ceb3a996607ee, 46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062, 4928096212b78262dbbeab3b3abf2352278ce22d, 80ed79787da3311f76b4d71d0ce7ab992a9e134d, 43078449ad6236d839e4d707954d2e36b10a6706, 7fc162453cfb7b8e93edb16287a84ba0130cac38, 7cb1c5b32a2bfde961fff8d5204526b609bcb30a |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: staging: most: video: avoid double free on video register failure comp_register_videodev() allocates a video_device with video_device_alloc() and releases it if video_register_device() fails. This can double free the video_device when __video_register_device() reaches device_register() and that call fails: video_register_device() -> __video_register_device() -> device_register() fails -> put_device(&vdev->dev) -> v4l2_device_release() -> vdev->release(vdev) -> video_device_release(vdev) comp_register_videodev() -> video_device_release(mdev->vdev) Use video_device_release_empty() while registering the device so that registration failure paths do not free mdev->vdev through vdev->release(). comp_register_videodev() then releases mdev->vdev exactly once on failure. Restore video_device_release() after successful registration so the registered device keeps its normal lifetime handling. This issue was found by a static analysis tool I am developing.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eab231c0398a91fbd294672bfe9e0ff45b368246 <009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <430ad4ea06a0767fb44a08e2212ceb3a996607ee || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <4928096212b78262dbbeab3b3abf2352278ce22d || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <80ed79787da3311f76b4d71d0ce7ab992a9e134d || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <43078449ad6236d839e4d707954d2e36b10a6706 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <7fc162453cfb7b8e93edb16287a84ba0130cac38 || >=eab231c0398a91fbd294672bfe9e0ff45b368246 <7cb1c5b32a2bfde961fff8d5204526b609bcb30a | 009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb, 430ad4ea06a0767fb44a08e2212ceb3a996607ee, 46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062, 4928096212b78262dbbeab3b3abf2352278ce22d, 80ed79787da3311f76b4d71d0ce7ab992a9e134d, 43078449ad6236d839e4d707954d2e36b10a6706, 7fc162453cfb7b8e93edb16287a84ba0130cac38, 7cb1c5b32a2bfde961fff8d5204526b609bcb30a |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: staging: most: video: avoid double free on video register failure comp_register_videodev() allocates a video_device with video_device_alloc() and releases it if video_register_device() fails. This can double free the video_device when __video_register_device() reaches device_register() and that call fails: video_register_device() -> __video_register_device() -> device_register() fails -> put_device(&vdev->dev) -> v4l2_device_release() -> vdev->release(vdev) -> video_device_release(vdev) comp_register_videodev() -> video_device_release(mdev->vdev) Use video_device_release_empty() while registering the device so that registration failure paths do not free mdev->vdev through vdev->release(). comp_register_videodev() then releases mdev->vdev exactly once on failure. Restore video_device_release() after successful registration so the registered device keeps its normal lifetime handling. This issue was found by a static analysis tool I am developing.
Quoted source text, attributed separately from HOL analysis.