{"id":"CVE-2026-31599","summary":"media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections\n\nsyzbot reported a general protection fault in vidtv_psi_desc_assign [1].\n\nvidtv_psi_pmt_stream_init() can return NULL on memory allocation\nfailure, but vidtv_channel_pmt_match_sections() does not check for\nthis. When tail is NULL, the subsequent call to\nvidtv_psi_desc_assign(&tail-\u003edescriptor, desc) dereferences a NULL\npointer offset, causing a general protection fault.\n\nAdd a NULL check after vidtv_psi_pmt_stream_init(). On failure, clean\nup the already-allocated stream chain and return.\n\n[1]\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nRIP: 0010:vidtv_psi_desc_assign+0x24/0x90 drivers/media/test-drivers/vidtv/vidtv_psi.c:629\nCall Trace:\n \u003cTASK\u003e\n vidtv_channel_pmt_match_sections drivers/media/test-drivers/vidtv/vidtv_channel.c:349 [inline]\n vidtv_channel_si_init+0x1445/0x1a50 drivers/media/test-drivers/vidtv/vidtv_channel.c:479\n vidtv_mux_init+0x526/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:519\n vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 [inline]\n vidtv_start_feed+0x33e/0x4d0 drivers/media/test-drivers/vidtv/vidtv_bridge.c:239","modified":"2026-06-18T03:54:45.030099067Z","published":"2026-04-24T14:42:23.961Z","related":["CGA-v6vf-xc72-22p3","openSUSE-SU-2026:10703-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31599.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/07c1e474cf9acf777f09d14a8f8dfcef5b84e46f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2dff11fb5098ae453651f8f77e94ad499c078022"},{"type":"WEB","url":"https://git.kernel.org/stable/c/54e18a23e62e81b8335cec3e8e9c5cb33fd88665"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c986b77200b5ea754ba6636deacc7e0942fec9b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/93d9e747a9e8a5ca9e3c5e37dcff76b40399139f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b7efb4c94797c504a1c678edb48c2aa311d3309f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b832cfd516b8504e95884622cee60bf9a39b7945"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e589de36da106ef739ba98f66f5a5c2023370706"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f8e1fc918a9fe67103bcda01d20d745f264d00a7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31599.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31599"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f90cf6079bf67988f8b1ad1ade70fc89d0080905"},{"fixed":"54e18a23e62e81b8335cec3e8e9c5cb33fd88665"},{"fixed":"5c986b77200b5ea754ba6636deacc7e0942fec9b"},{"fixed":"93d9e747a9e8a5ca9e3c5e37dcff76b40399139f"},{"fixed":"b7efb4c94797c504a1c678edb48c2aa311d3309f"},{"fixed":"e589de36da106ef739ba98f66f5a5c2023370706"},{"fixed":"2dff11fb5098ae453651f8f77e94ad499c078022"},{"fixed":"b832cfd516b8504e95884622cee60bf9a39b7945"},{"fixed":"07c1e474cf9acf777f09d14a8f8dfcef5b84e46f"},{"fixed":"f8e1fc918a9fe67103bcda01d20d745f264d00a7"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31599.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.10.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.136"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.83"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.24"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.14"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.20.0"},{"fixed":"7.0.1"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31599.json"}}],"schema_version":"1.7.5"}