CVE-2026-31473
published 2026-04-22CVE-2026-31473: In the Linux kernel, the following vulnerability has been resolved: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex MEDIA_REQUEST_IOC_REINIT…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
MEDIA_REQUEST_IOC_REINIT can run concurrently with VIDIOC_REQBUFS(0)
queue teardown paths. This can race request object cleanup against vb2
queue cancellation and lead to use-after-free reports.
We already serialize request queueing against STREAMON/OFF with
req_queue_mutex. Extend that serialization to REQBUFS, and also take
the same mutex in media_request_ioctl_reinit() so REINIT is in the
same exclusion domain.
This keeps request cleanup and queue cancellation from running in
parallel for request-capable devices.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 331242998a7ade5c2f65e14988901614629f3db5 | 331242998a7ade5c2f65e14988901614629f3db5 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 2c685e99efb3b3bd2b78699fba6b1cf321975db0 | 2c685e99efb3b3bd2b78699fba6b1cf321975db0 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 585fd9a2063dacce8b2820f675ef23d5d17434c5 | 585fd9a2063dacce8b2820f675ef23d5d17434c5 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 1a0d9083c24fbd5d22f7100f09d11e4d696a5f01 | 1a0d9083c24fbd5d22f7100f09d11e4d696a5f01 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < d8549a453d5bdc0a71de66ad47a1106703406a56 | d8549a453d5bdc0a71de66ad47a1106703406a56 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < 72b9e81e0203f03c40f3adb457f55bd4c8eb112d | 72b9e81e0203f03c40f3adb457f55bd4c8eb112d |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < cf2023e84f0888f96f4b65dc0804e7f3651969c1 | cf2023e84f0888f96f4b65dc0804e7f3651969c1 |
| linux | linux | >= 6093d3002eabd7c2913d97f1d1f4ce34b072acf9 < bef4f4a88b73e4cc550d25f665b8a9952af22773 | bef4f4a88b73e4cc550d25f665b8a9952af22773 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.20.1 < 5.10.253 | 5.10.253 |
| linux | linux_kernel | >= 5.11 < 5.15.203 | 5.15.203 |
| linux | linux_kernel | >= 5.16 < 6.1.168 | 6.1.168 |
| linux | linux_kernel | >= 6.13 < 6.18.21 | 6.18.21 |
| linux | linux_kernel | >= 6.19 < 6.19.11 | 6.19.11 |
| linux | linux_kernel | >= 6.2 < 6.6.131 | 6.6.131 |
| linux | linux_kernel | >= 6.7 < 6.12.80 | 6.12.80 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3535-jv42-vvc3: In the Linux kernel, the following vulnerability has been resolved:
media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
MEDIA_REQUEST
ghsa_unreviewed·2026-04-22
CVE-2026-31473 GHSA-3535-jv42-vvc3: In the Linux kernel, the following vulnerability has been resolved:
media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
MEDIA_REQUEST
In the Linux kernel, the following vulnerability has been resolved:
media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
MEDIA_REQUEST_IOC_REINIT can run concurrently with VIDIOC_REQBUFS(0)
queue teardown paths. This can race request object cleanup against vb2
queue cancellation and lead to use-after-free reports.
We already serialize request queueing against STREAMON/OFF with
req_queue_mutex. Extend that serialization to REQBUFS, and also take
the same mutex in media_request_ioctl_reinit() so REINIT is in the
same exclusion domain.
This keeps request cleanup and queue cancellation from running in
parallel for request-capable devices.
Red Hat
kernel: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
vendor_redhat·2026-04-22·CVSS 7.0
CVE-2026-31473 [MEDIUM] CWE-364 kernel: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
kernel: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
A flaw was found in the Linux kernel's media, mc, and v4l2 subsystems. A race condition can occur when MEDIA_REQUEST_IOC_REINIT runs concurrently with VIDIOC_REQBUFS(0) queue teardown paths, leading to a use-after-free vulnerability. This flaw could allow a local attacker to cause a system crash (denial of service) or potentially execute arbitrary code with elevated privileges.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterpris
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1a0d9083c24fbd5d22f7100f09d11e4d696a5f01https://git.kernel.org/stable/c/2c685e99efb3b3bd2b78699fba6b1cf321975db0https://git.kernel.org/stable/c/331242998a7ade5c2f65e14988901614629f3db5https://git.kernel.org/stable/c/585fd9a2063dacce8b2820f675ef23d5d17434c5https://git.kernel.org/stable/c/72b9e81e0203f03c40f3adb457f55bd4c8eb112dhttps://git.kernel.org/stable/c/bef4f4a88b73e4cc550d25f665b8a9952af22773https://git.kernel.org/stable/c/cf2023e84f0888f96f4b65dc0804e7f3651969c1https://git.kernel.org/stable/c/d8549a453d5bdc0a71de66ad47a1106703406a56
2026-04-22
Published