cbcvebase.
CVE-2026-31473
published 2026-04-22

CVE-2026-31473: In the Linux kernel, the following vulnerability has been resolved: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex MEDIA_REQUEST_IOC_REINIT…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex MEDIA_REQUEST_IOC_REINIT can run concurrently with VIDIOC_REQBUFS(0) queue teardown paths. This can race request object cleanup against vb2 queue cancellation and lead to use-after-free reports. We already serialize request queueing against STREAMON/OFF with req_queue_mutex. Extend that serialization to REQBUFS, and also take the same mutex in media_request_ioctl_reinit() so REINIT is in the same exclusion domain. This keeps request cleanup and queue cancellation from running in parallel for request-capable devices.

Affected

19 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 331242998a7ade5c2f65e14988901614629f3db5331242998a7ade5c2f65e14988901614629f3db5
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 2c685e99efb3b3bd2b78699fba6b1cf321975db02c685e99efb3b3bd2b78699fba6b1cf321975db0
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 585fd9a2063dacce8b2820f675ef23d5d17434c5585fd9a2063dacce8b2820f675ef23d5d17434c5
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 1a0d9083c24fbd5d22f7100f09d11e4d696a5f011a0d9083c24fbd5d22f7100f09d11e4d696a5f01
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < d8549a453d5bdc0a71de66ad47a1106703406a56d8549a453d5bdc0a71de66ad47a1106703406a56
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 72b9e81e0203f03c40f3adb457f55bd4c8eb112d72b9e81e0203f03c40f3adb457f55bd4c8eb112d
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < cf2023e84f0888f96f4b65dc0804e7f3651969c1cf2023e84f0888f96f4b65dc0804e7f3651969c1
linuxlinux>= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < bef4f4a88b73e4cc550d25f665b8a9952af22773bef4f4a88b73e4cc550d25f665b8a9952af22773
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.20.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1686.1.168
linuxlinux_kernel>= 6.13 < 6.18.216.18.21
linuxlinux_kernel>= 6.19 < 6.19.116.19.11
linuxlinux_kernel>= 6.2 < 6.6.1316.6.131
linuxlinux_kernel>= 6.7 < 6.12.806.12.80

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.