Use After Free Vulnerability in Linux Kernel Media Component by Vendor
CVE-2026-97513
What is CVE-2026-97513?
A use after free vulnerability has been identified in the Linux kernel's media subsystem, specifically in the wave5 media chip component. This flaw arises when an IRQ thread acquires a spinlock after the m2m_ctx is released but before it is removed from the list of active instances. Consequently, if the IRQ thread attempts to access the m2m_ctx that has already been freed, it leads to a null pointer dereference, potentially compromising system stability and security. Proper handling and timely updates are essential for mitigating this vulnerability.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 04cda0b5c4ca3f61cbc86e41ead3c462c8cfd659
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7cdbd7bb21949a8fda10c7104a2b12ee363cbf5c
Linux 0 < 6.18.53