{"id":"CVE-2026-46205","summary":"staging: media: atomisp: Disallow all private IOCTLs","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: atomisp: Disallow all private IOCTLs\n\nDisallow all private IOCTLs. These aren't quite as safe as one could\nassume of IOCTL handlers; disable them for now. Instead of removing the\ncode, return in the beginning of the function if cmd is non-zero in order\nto keep static checkers happy.","modified":"2026-07-22T18:22:53.791357351Z","published":"2026-05-28T09:40:23.117Z","related":["SUSE-SU-2026:3130-1","SUSE-SU-2026:3166-1","openSUSE-SU-2026:10954-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46205.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2b7eb2c5dc72f0fc954ac4aa155f9e285e937f7c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654"},{"type":"WEB","url":"https://git.kernel.org/stable/c/64e85679beafe082fc2e70a557ec356c7fd27548"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6850a439f8d23d4979624f1d6880d3118d473a28"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6f1ce75a75c65061e7a720c3d0ee5f8adab7a2d3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8774f8cb661f57ae43cc3bc0509d16ef1f406e45"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8c7a281a99224a5b9af99c4dcd98d68eea75926c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c7848b67ef10f581114b6a2f52b160fc20eb52c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ceb1b5f910e58986ea544ff8c9c2f23ae9a52414"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46205.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46205"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a49d25364dfb9f8a64037488a39ab1f56c5fa419"},{"fixed":"51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ad85094b293e40e7a2f831b0311a389d952ebd5e"},{"fixed":"64e85679beafe082fc2e70a557ec356c7fd27548"},{"fixed":"8774f8cb661f57ae43cc3bc0509d16ef1f406e45"},{"fixed":"ceb1b5f910e58986ea544ff8c9c2f23ae9a52414"},{"fixed":"8c7a281a99224a5b9af99c4dcd98d68eea75926c"},{"fixed":"6f1ce75a75c65061e7a720c3d0ee5f8adab7a2d3"},{"fixed":"c7848b67ef10f581114b6a2f52b160fc20eb52c9"},{"fixed":"6850a439f8d23d4979624f1d6880d3118d473a28"},{"fixed":"2b7eb2c5dc72f0fc954ac4aa155f9e285e937f7c"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46205.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.12.0"},{"fixed":"4.18"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.140"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.90"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.32"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46205.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}