Answer in brief
CVE-2026-89870 records a Unknown severity vulnerability in media: zoran: Avoid freeing a registered video_device twice. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <3ad6cf27505017a6794f5f96c31218c2291e951b || >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <c4acac8cdc005b2d14b6cef5e215d264212857f3 || >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <4d99d8d0d895489064783601a516bd45812fa992 || >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <f1c4f3885df1f09bcab5296d86834d104f865e86 || >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <672dbccf4351370dad002d3c78dbb29ca1588f22 || >=82e3a496eb56da0b9f29fdc5b63cedb3289e91de <0735e0b5a96761a9ce277a238e834008ad92a0a5 || bd01629315ffd5b63da91d0bd529a77d30e55028 || ff3357bffd9fb78f59762d8955afc7382a279079 || c1ba65100a359fe28cfe37e09e10c99f247cbf1e || 1e501ec38796f43e995731d1bcd4173cb1ccfce0 || >=5.10.110 <5.11 || >=5.15.33 <5.16 || >=5.16.19 <5.17 || >=5.17.2 <5.18 | 3ad6cf27505017a6794f5f96c31218c2291e951b, c4acac8cdc005b2d14b6cef5e215d264212857f3, 4d99d8d0d895489064783601a516bd45812fa992, f1c4f3885df1f09bcab5296d86834d104f865e86, 672dbccf4351370dad002d3c78dbb29ca1588f22, 0735e0b5a96761a9ce277a238e834008ad92a0a5, 5.11, 5.16, 5.17, 5.18 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_device twice zoran_init_video_device() installs zoran_vdev_release() as the video_device release callback through zoran_template. After video_register_device() succeeds, video_unregister_device() drops the registered video_device reference and the V4L2 core eventually invokes that release callback, which kfree()s the video_device. zoran_exit_video_devices() called video_unregister_device() and then kfree(zr->video_dev), so device teardown could free the same video_device twice. Remove the direct kfree() and clear the cached pointer after unregistering. The pre-registration failure path keeps its manual free because the video_device was not registered there. This issue was found by a static analysis checker and confirmed by manual source review.
Quoted source text, attributed separately from HOL analysis.