Answer in brief
CVE-2026-93070 records a Unknown severity vulnerability in media: ipu6: Do not free aux device pdata after init. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cb3117b074aefb0320d8d728a0a7f277a121adbd <faa1eb97f0e66bf122f44b62be6b323f86333e9f || >=cb3117b074aefb0320d8d728a0a7f277a121adbd <5323ed5a7bb2568191ec676b2035b0396105aa05 || >=cb3117b074aefb0320d8d728a0a7f277a121adbd <7d102d1f0631807a491a140f67c9628dea85dfd2 || >=cb3117b074aefb0320d8d728a0a7f277a121adbd <9be07216af4cfc4813e1a46ce26407d31ea845de | faa1eb97f0e66bf122f44b62be6b323f86333e9f, 5323ed5a7bb2568191ec676b2035b0396105aa05, 7d102d1f0631807a491a140f67c9628dea85dfd2, 9be07216af4cfc4813e1a46ce26407d31ea845de |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after init ipu6_bus_initialize_device() stores the isys/psys pdata pointer in struct ipu6_bus_device and initializes the auxiliary device. After that point, error unwinding must drop the auxiliary device reference and let ipu6_bus_release() free both the bus device and adev->pdata. The isys and psys init paths already call put_device() when MMU initialization fails, and ipu6_bus_add_device() calls auxiliary_device_uninit() on auxiliary_device_add() failure. Both paths therefore run the bus release callback. The extra kfree(pdata) in the callers can release the same object a second time. Remove the manual pdata frees after the auxiliary device has been initialized. This issue was found by a static analysis checker and confirmed by manual source review.
Quoted source text, attributed separately from HOL analysis.