---
id: CVE-2026-46310
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: renesas: vsp1: Fix NULL pointer deref on module unload

  When unloading the module on gen 4, we hit a NULL pointer dereference.
  This is caused by the cleanup code…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: renesas: vsp1: Fix NULL pointer deref on module unload

  When unloading the module on gen 4, we hit a NULL pointer dereference.
  This is caused by the cleanup code…
severity: none
published: '2026-06-08'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46310'
references:
  - url: 'https://git.kernel.org/stable/c/58b1e9664d8f74d55d8411cc7a7b275a76a6f24f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bfb2081ba00afbbd15a5ed1ed1acdc3edeea5a98'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c4bb1515b26663e5230603892e67f2cc7df9f0ca'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.0016
epssPercentile: 0.04384
ingestedAt: '2026-07-08T12:51:00.716Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: renesas: vsp1: Fix NULL pointer deref on module unload

When unloading the module on gen 4, we hit a NULL pointer dereference.
This is caused by the cleanup code calling vsp1_drm_cleanup() where it
should be calling vsp1_vspx_cleanup().

Fix this by checking the IP version and calling the drm or vspx function
accordingly, the same way as the init code does.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
