CVE-2026-89871
media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
Description
In the Linux kernel, the following vulnerability has been resolved: media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure kthread_run() returns an ERR_PTR on failure, not NULL. When start_streaming() fails, data->kthread_vid_cap is left holding this error pointer instead of being cleared. This causes two subsequent bugs: 1. A future call to start_streaming() sees a non-NULL kthread_vid_cap and returns 0 (success) immediately, without actually starting the capture thread. 2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which is false for an error pointer, and proceeds to call kthread_stop() on the error pointer, leading to a kernel crash. Fix this by resetting kthread_vid_cap to NULL on failure before jumping to the error path.
INFO
Published Date :
Sept. 16, 2026, 11:16 a.m.
Last Modified :
Sept. 16, 2026, 11:16 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Update the Linux kernel to the corrected version.
- Ensure kthread_vid_cap is reset to NULL on failure.
- Verify proper error handling in streaming functions.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-89871.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-89871 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-89871
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-89871 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-89871 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 16, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure kthread_run() returns an ERR_PTR on failure, not NULL. When start_streaming() fails, data->kthread_vid_cap is left holding this error pointer instead of being cleared. This causes two subsequent bugs: 1. A future call to start_streaming() sees a non-NULL kthread_vid_cap and returns 0 (success) immediately, without actually starting the capture thread. 2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which is false for an error pointer, and proceeds to call kthread_stop() on the error pointer, leading to a kernel crash. Fix this by resetting kthread_vid_cap to NULL on failure before jumping to the error path. Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/89xxx/CVE-2026-89871.json">CVE-2026-89871</a> Added Reference https://git.kernel.org/stable/c/0e7f2cd72a4f9268ee09a13b13f3339e7cc71557 Added Reference https://git.kernel.org/stable/c/0fac63cac6689588da530764ccb6ba55ee8e4d8b Added Reference https://git.kernel.org/stable/c/3d1b10d81fe54852ed953f4129577b733bbd6907 Added Reference https://git.kernel.org/stable/c/52fd9d80c0cea7bf09e7ee36cad316e5c39b7fe6 Added Reference https://git.kernel.org/stable/c/5c35d380bea60503c4fe0986fe1de6a3263282b3 Added Reference https://git.kernel.org/stable/c/76e379754ba618989f6215be608d5c04774a611d Added Reference https://git.kernel.org/stable/c/968c5213e34c48d35febdfd09cf3dc58ad039140 Added Reference https://git.kernel.org/stable/c/db0f4531aa55cfb0171684ebfffe3ff04b79d5a8