CVE-2026-43162

In the Linux kernel, the following vulnerability has been resolved: media: tegra-video: Fix memory leak in __tegra_channel_try_format() The state object allocated by __v4l2_subdev_state_alloc() must be freed with __v4l2_subdev_state_free() when it is no longer needed. In __tegra_channel_try_format(), two error paths return directly after v4l2_subdev_call() fails, without freeing the allocated 'sd_state' object. This violates the requirement and causes a memory leak. Fix this by introducing a cleanup label and using goto statements in the error paths to ensure that __v4l2_subdev_state_free() is always called before the function returns.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

13 May 2026, 21:19

Type Values Removed Values Added
CWE CWE-401
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/2dff8966a3a889dd9d248a7e15d963b4097efcc5 - () https://git.kernel.org/stable/c/2dff8966a3a889dd9d248a7e15d963b4097efcc5 - Patch
References () https://git.kernel.org/stable/c/3ca2f09061736e72ef25eec2597d00f7f44094d3 - () https://git.kernel.org/stable/c/3ca2f09061736e72ef25eec2597d00f7f44094d3 - Patch
References () https://git.kernel.org/stable/c/43e5302d22334f1183dec3e0d5d8007eefe2817c - () https://git.kernel.org/stable/c/43e5302d22334f1183dec3e0d5d8007eefe2817c - Patch
References () https://git.kernel.org/stable/c/6c6f419fa9c44a4b7149b0292e01bff47308ba14 - () https://git.kernel.org/stable/c/6c6f419fa9c44a4b7149b0292e01bff47308ba14 - Patch
References () https://git.kernel.org/stable/c/ca921be7a1174d5d58b28f84b683c2c0079f18c5 - () https://git.kernel.org/stable/c/ca921be7a1174d5d58b28f84b683c2c0079f18c5 - Patch
References () https://git.kernel.org/stable/c/d92e9a18f97a1d19d4c2ff81dcfbe43591f75b5a - () https://git.kernel.org/stable/c/d92e9a18f97a1d19d4c2ff81dcfbe43591f75b5a - Patch

06 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 12:16

Updated : 2026-05-13 21:19


NVD link : CVE-2026-43162

Mitre link : CVE-2026-43162

CVE.ORG link : CVE-2026-43162


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime