{"id":"CVE-2026-64421","summary":"media: nxp: imx8-isi: Fix use-after-free on remove","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix use-after-free on remove\n\nKASAN reports a slab-use-after-free in __media_entity_remove_link()\nduring rmmod of imx8_isi:\n\n  BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650\n  Read of size 2 at addr ffff0000d47cb02a by task rmmod/724\n\n  Call trace:\n   __media_entity_remove_link+0x608/0x650\n   __media_entity_remove_links+0x78/0x144\n   __media_device_unregister_entity+0x150/0x280\n   media_device_unregister_entity+0x48/0x68\n   v4l2_device_unregister_subdev+0x158/0x300\n   v4l2_async_unbind_subdev_one+0x22c/0x358\n   v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0\n   v4l2_async_nf_unregister+0x5c/0x14c\n   mxc_isi_remove+0x124/0x2a0 [imx8_isi]\n\n  Allocated by task 249:\n   __kmalloc_noprof+0x27c/0x690\n   mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]\n\n  Freed by task 724:\n   kfree+0x1e4/0x5b0\n   mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]\n   mxc_isi_remove+0x11c/0x2a0 [imx8_isi]\n\nThe problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup()\nbefore mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media\nentity pads, but the subsequent v4l2 cleanup still tries to remove\nmedia links that reference those pads.\n\nFix this by calling mxc_isi_v4l2_cleanup() before\nmxc_isi_crossbar_cleanup() to ensure all media entities are properly\nunregistered while the pads are still valid.","modified":"2026-08-18T03:31:01.472780025Z","published":"2026-07-25T08:50:59.926Z","related":["openSUSE-SU-2026:11476-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64421.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/b670bf89824ede5d07d20bb9bfbafb754846081d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ba2aa5d325270cd965c44458c5ff5ab555e6af51"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c12a5b2261351cd3b03921ce4720332ff5184b50"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d22fb719654bfde6f682c9f14629f5f9534175b7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ef382a6baf0a95cf199fdf6bba2fd08e58b0a249"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64421.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64421"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"cf21f328fcafacf4f96e7a30ef9dceede1076378"},{"fixed":"d22fb719654bfde6f682c9f14629f5f9534175b7"},{"fixed":"ba2aa5d325270cd965c44458c5ff5ab555e6af51"},{"fixed":"ef382a6baf0a95cf199fdf6bba2fd08e58b0a249"},{"fixed":"c12a5b2261351cd3b03921ce4720332ff5184b50"},{"fixed":"b670bf89824ede5d07d20bb9bfbafb754846081d"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64421.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64421.json"}}],"schema_version":"1.9.0"}