Answer in brief
CVE-2026-89896 records a Unknown severity vulnerability in media: cedrus: fix memory leak in cedrus_init_ctrls(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <6fabacc3b79a528450aef4c32464da2ec681049e || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <729a1ffab968b3c493f61d1cd683f5bafec500ea || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <ce5693b6e3a693fcdc3800af309363f6250104c8 || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <22441be29ec27c693f40c1ef499093275ef529d1 || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <79fd0b0161506fc9507bf7a6fe4c975a857a5be8 || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <f78cf36cabf911da348ea80e4e9f430d74f6905c || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <81aa608ac3a56cdd4aab0bd12442ed529a24ba31 || >=50e761516f2b8c0cdeb31a8c6ca1b4ef98cd13f1 <9df2fbe563194da1967a5db083442186c1323efe | 6fabacc3b79a528450aef4c32464da2ec681049e, 729a1ffab968b3c493f61d1cd683f5bafec500ea, ce5693b6e3a693fcdc3800af309363f6250104c8, 22441be29ec27c693f40c1ef499093275ef529d1, 79fd0b0161506fc9507bf7a6fe4c975a857a5be8, f78cf36cabf911da348ea80e4e9f430d74f6905c, 81aa608ac3a56cdd4aab0bd12442ed529a24ba31, 9df2fbe563194da1967a5db083442186c1323efe |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: media: cedrus: fix memory leak in cedrus_init_ctrls() In cedrus_init_ctrls(), the V4L2 control handler is initialized before allocating memory for ctx->ctrls. If this allocation fails, the function returns -ENOMEM without freeing the previously allocated handler resources, leading to a memory leak. Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation failure path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64 allyesconfig build showed no new warnings. As we do not have an Allwinner SoC or board with a Cedrus VPU available to test with, no runtime testing was able to be performed.
Quoted source text, attributed separately from HOL analysis.