CVE-2026-68207

critical

Description

In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: unwind v4l2 device registration on probe error If the vpe_top resource is missing, vpe_probe() returns -ENODEV after v4l2_device_register() has succeeded. Probe failures do not call the driver's remove callback, so the v4l2 device remains registered on that error path. Route that failure through the existing v4l2_device_unregister() unwind label, matching the other errors after v4l2_device_register().

References

https://git.kernel.org/stable/c/fcbbaf9cb9722a82f0221c56114037fc537f4ada

https://git.kernel.org/stable/c/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6

https://git.kernel.org/stable/c/7e6521dd747eca3cb3d4cd3ddcf20f266494f63d

https://git.kernel.org/stable/c/7d383357905de975e1dbde639e5fa7477075d104

https://git.kernel.org/stable/c/4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9

https://git.kernel.org/stable/c/0f0a60c000876bcd808a70d602c758c2e64c77d8

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-19

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00209