CVE-2026-43218
Published: May 9, 2026Last modified: May 9, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: media: i2c/tw9903: Fix potential memory leak in tw9903_probe() In one of the error paths in tw9903_probe(), the memory allocated in v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() is not freed. Fix that by calling v4l2_ctrl_handler_free() on the handler in that error path.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 5.5 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.167-r0) |
| 25 LTS | linux-lts | Fixed (6.12.80-r0) | |
| Stream | linux-lts | Fixed (6.12.76-r0) |
References
- https://git.kernel.org/stable/c/32f0493506313775d3bd448de34762b6538da6bd
- https://git.kernel.org/stable/c/92537a15780b6d0281fd8286f93fbc3652e35f48
- https://git.kernel.org/stable/c/9cb9eca33d20316ed3c7a938793b8735ac3e128b
- https://git.kernel.org/stable/c/9cea16fea47e5553f51d10957677ff735b1eff03
- https://git.kernel.org/stable/c/a114918270f0d95c607d69b03a244e6afe54813f
- https://git.kernel.org/stable/c/add02a3fb1fd71b004f0ed824cbac00f850de558
- https://git.kernel.org/stable/c/cc7aeed33e4f55c76f35f0fca73e4dfe12a63a3a
- https://git.kernel.org/stable/c/e54aa17c968c4de2c5f7b7ea390c63d33c07513b