{"id":"CVE-2026-89870","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: zoran: Avoid freeing a registered video_device twice\n\nzoran_init_video_device() installs zoran_vdev_release() as the\nvideo_device release callback through zoran_…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: zoran: Avoid freeing a registered video_device twice\n\nzoran_init_video_device() installs zoran_vdev_release() as the\nvideo_device release callback through zoran_…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < 3ad6cf27505017a6794f5f96c31218c2291e951b","Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < c4acac8cdc005b2d14b6cef5e215d264212857f3","Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < 4d99d8d0d895489064783601a516bd45812fa992","Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < f1c4f3885df1f09bcab5296d86834d104f865e86","Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < 672dbccf4351370dad002d3c78dbb29ca1588f22","Linux >= 82e3a496eb56da0b9f29fdc5b63cedb3289e91de < 0735e0b5a96761a9ce277a238e834008ad92a0a5","Linux bd01629315ffd5b63da91d0bd529a77d30e55028","Linux ff3357bffd9fb78f59762d8955afc7382a279079","Linux c1ba65100a359fe28cfe37e09e10c99f247cbf1e","Linux 1e501ec38796f43e995731d1bcd4173cb1ccfce0","Linux >= 5.10.110 < 5.11","Linux >= 5.15.33 < 5.16","Linux >= 5.16.19 < 5.17","Linux >= 5.17.2 < 5.18","Linux 5.18"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:14.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89870","references":[{"url":"https://git.kernel.org/stable/c/0735e0b5a96761a9ce277a238e834008ad92a0a5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ad6cf27505017a6794f5f96c31218c2291e951b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d99d8d0d895489064783601a516bd45812fa992","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/672dbccf4351370dad002d3c78dbb29ca1588f22","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4acac8cdc005b2d14b6cef5e215d264212857f3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1c4f3885df1f09bcab5296d86834d104f865e86","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.988Z","epss":0.00164,"epssPercentile":0.06047,"slug":"CVE-2026-89870","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmedia: zoran: Avoid freeing a registered video_device twice\n\nzoran_init_video_device() installs zoran_vdev_release() as the\nvideo_device release callback through zoran_template. After\nvideo_register_device() succeeds, video_unregister_device() drops the\nregistered video_device reference and the V4L2 core eventually invokes\nthat release callback, which kfree()s the video_device.\n\nzoran_exit_video_devices() called video_unregister_device() and then\nkfree(zr->video_dev), so device teardown could free the same\nvideo_device twice.\n\nRemove the direct kfree() and clear the cached pointer after\nunregistering. The pre-registration failure path keeps its manual free\nbecause the video_device was not registered there.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205176,"id":"CVE-2026-89870","ts":1789570705594,"field":"cvss","old":null,"new":"7.8"},{"seq":205175,"id":"CVE-2026-89870","ts":1789570705594,"field":"severity","old":"none","new":"high"}]}