---
id: CVE-2026-93070
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: ipu6: Do not free aux device pdata after init

  ipu6_bus_initialize_device() stores the isys/psys pdata pointer in
  struct ipu6_bus_device and initializes the auxi…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  media: ipu6: Do not free aux device pdata after init

  ipu6_bus_initialize_device() stores the isys/psys pdata pointer in
  struct ipu6_bus_device and initializes the auxi…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cb3117b074aefb0320d8d728a0a7f277a121adbd <
    faa1eb97f0e66bf122f44b62be6b323f86333e9f
  - >-
    Linux >= cb3117b074aefb0320d8d728a0a7f277a121adbd <
    5323ed5a7bb2568191ec676b2035b0396105aa05
  - >-
    Linux >= cb3117b074aefb0320d8d728a0a7f277a121adbd <
    7d102d1f0631807a491a140f67c9628dea85dfd2
  - >-
    Linux >= cb3117b074aefb0320d8d728a0a7f277a121adbd <
    9be07216af4cfc4813e1a46ce26407d31ea845de
  - Linux 6.10
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:18:20.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93070'
references:
  - url: 'https://git.kernel.org/stable/c/5323ed5a7bb2568191ec676b2035b0396105aa05'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7d102d1f0631807a491a140f67c9628dea85dfd2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9be07216af4cfc4813e1a46ce26407d31ea845de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/faa1eb97f0e66bf122f44b62be6b323f86333e9f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00175
epssPercentile: 0.06155
ingestedAt: '2026-09-17T16:21:47.765Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

media: ipu6: Do not free aux device pdata after init

ipu6_bus_initialize_device() stores the isys/psys pdata pointer in
struct ipu6_bus_device and initializes the auxiliary device. After that
point, error unwinding must drop the auxiliary device reference and let
ipu6_bus_release() free both the bus device and adev->pdata.

The isys and psys init paths already call put_device() when MMU
initialization fails, and ipu6_bus_add_device() calls
auxiliary_device_uninit() on auxiliary_device_add() failure. Both paths
therefore run the bus release callback. The extra kfree(pdata) in the
callers can release the same object a second time.

Remove the manual pdata frees after the auxiliary device has been
initialized.

This issue was found by a static analysis checker and confirmed by
manual source review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
